DOM-based XSS Vulnerability in Jexactyl Game Management Panel
CVE-2026-33061

5.8MEDIUM

Key Information:

Vendor

Jexactyl

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33061?

The Jexactyl Game Management Panel has a vulnerability that exposes users to potential cross-site scripting (XSS) attacks. This occurs in versions prior to a specific commit, where server-side objects are improperly injected into client-side JavaScript without adequate encoding protections. Attackers can craft malicious inputs that, when rendered, execute arbitrary scripts. This vulnerability poses significant risks as it can affect all users viewing compromised pages, leading to unauthorized actions and data theft.

Affected Version(s)

Jexactyl >= 025e8dbb0daaa04054276bda814d922cf4af58da, < e28edb204e80efab628d1241198ea4f079779cfd

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.