Payment Processing Issue in Jexactyl Game Management Panel by Jexactyl
CVE-2026-107852

7.1HIGH

Key Information:

Vendor

Jexactyl

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107852?

The Jexactyl game management panel contains a vulnerability in its billing system prior to version 4.0.5. The POST /api/client/billing/stripe/process endpoint incorrectly handles user-supplied Stripe Checkout Session information when the payment status is marked as paid. It fails to validate the total amount and currency against the associated order, potentially allowing an authenticated user to successfully process a payment with a lower amount or a different currency than intended. This could lead to unauthorized provisioning or changes to server resources at significantly less than the expected cost. The issue has been addressed in the latest release, ensuring proper validation during the payment process.

Affected Version(s)

Jexactyl < 4.0.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.