CVE-2026-107854

MEDIUMCVSS 5.4/10

Last modified

CVE-2026-107854 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account.

Description

Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
JexactylJexactyl>= 4.0.0, < 4.0.5

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-107854?
Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.
How severe is CVE-2026-107854?
CVE-2026-107854 has a CVSS score of 5.4/10 (MEDIUM severity).
How do I fix CVE-2026-107854?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-107854?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST