- Version
- 2.5(32)
- Platform
- Windows
Summary:
Two external players gained access to Creative / Dev-level functionality on a non-creative dedicated server without being granted admin rights. This is confirmed by server logs and should not be possible.
Server setup:
Dedicated server, Creative OFF, no admin tools enabled at time of incident, crossplay enabled (Steam + EOS + EAC).
Offending players (NOT admins):
NOT involved (legitimate admins):
Snalle, HappiVaje, Izqu — confirmed by logs, different SteamIDs/IPs. Admin tools were enabled only after the incident for investigation.
Timeline (from logs):
Why this is not admin error:
Creative disabled, no permissions granted, no overlap with admin logins, unauthorized actions occurred prior to admin tool usage.
Why this is a security issue:
Normal user authentication resulted in access to restricted dev/creative functionality. Indicates permission leakage or unintended authorization path (possibly EOS/crossplay related).
Attachments:
Full server logs included (timestamps preserved).
Request:
Please escalate to dev/security team to review creative/dev permission gating and authorization boundaries.
Log(files) in this post
— Server Admin Team
Two external players gained access to Creative / Dev-level functionality on a non-creative dedicated server without being granted admin rights. This is confirmed by server logs and should not be possible.
Server setup:
Dedicated server, Creative OFF, no admin tools enabled at time of incident, crossplay enabled (Steam + EOS + EAC).
Offending players (NOT admins):
- insegt
SteamID: 76561198996443610
EOS ID: EOS_00024ff69acd4a259a64d075e34ec50d
IP: 38.57.237.8
Auth: Steam OK / EOS OK / EAC OK - LIsland (also seen as lland / Lsland)
SteamID: 76561198350780269
EOS ID: EOS_0002d01c5f974a7cb53f61f6e6a685ef
Auth: Steam OK / EOS OK / EAC OK
NOT involved (legitimate admins):
Snalle, HappiVaje, Izqu — confirmed by logs, different SteamIDs/IPs. Admin tools were enabled only after the incident for investigation.
Timeline (from logs):
- 2026-02-03 ~16:21: insegt logs in via normal authentication path
- ~16:22: LIsland joins
- Both players perform Creative / Dev-level actions despite having no admin permissions
- Behavior observed before any admin tools were enabled
- Server was manually shut down by owner to prevent further impact
Why this is not admin error:
Creative disabled, no permissions granted, no overlap with admin logins, unauthorized actions occurred prior to admin tool usage.
Why this is a security issue:
Normal user authentication resulted in access to restricted dev/creative functionality. Indicates permission leakage or unintended authorization path (possibly EOS/crossplay related).
Attachments:
Full server logs included (timestamps preserved).
Request:
Please escalate to dev/security team to review creative/dev permission gating and authorization boundaries.
Log(files) in this post
— Server Admin Team
- Reproduction Steps
- [SECURITY BUG] Unauthorized Creative / Dev-Level Access on Non-Creative Dedicated Server
- Link to Logs
- https://jpst.it/4RD_0
- Link to Screenshot/Video
- https://youtube.com/@sweepersincgaming?si=IPbwwo5_u_yiI4BD