Game Management Panel Vulnerability in Jexactyl
CVE-2026-107854
5.4MEDIUM
What is CVE-2026-107854?
A vulnerability exists in Jexactyl, a customizable game management panel and billing system, across versions 4.0.0 to 4.0.5. The issue arises from the POST /api/client/billing/free/process endpoint, which does not appropriately restrict access based on ownership of the server. This flaw enables authenticated users to renew or unsuspend another user's billable server even when significant time remains until the scheduled renewal date. The vulnerability is mitigated in version 4.0.5, where proper checks have been implemented to ensure users can only manage servers they own.
Affected Version(s)
Jexactyl >= 4.0.0, < 4.0.5
