CVE-2026-107854

Source
https://cve.org/CVERecord?id=CVE-2026-107854
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107854.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107854
Aliases
  • GHSA-9xwv-p7r5-5h5p
Published
2026-10-09T20:31:02Z
Modified
2026-10-10T10:45:25Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check)
Details

Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107854.json"
}
References

Affected packages

Git / github.com/jexactyl/jexactyl

Affected ranges

Type
GIT
Repo
https://github.com/jexactyl/jexactyl
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.5"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107854.json"