Payment Processing Issue in Jexactyl Game Management Panel by Jexactyl
CVE-2026-107852
7.1HIGH
What is CVE-2026-107852?
The Jexactyl game management panel contains a vulnerability in its billing system prior to version 4.0.5. The POST /api/client/billing/stripe/process endpoint incorrectly handles user-supplied Stripe Checkout Session information when the payment status is marked as paid. It fails to validate the total amount and currency against the associated order, potentially allowing an authenticated user to successfully process a payment with a lower amount or a different currency than intended. This could lead to unauthorized provisioning or changes to server resources at significantly less than the expected cost. The issue has been addressed in the latest release, ensuring proper validation during the payment process.
Affected Version(s)
Jexactyl < 4.0.5
