5.4

CVE-2026-107854

Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check)

Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerJexactyl
≫
Produkt Jexactyl
Version >= 4.0.0, < 4.0.5
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5
https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-9xwv-p7r5-5h5p
https://github.com/Jexactyl/Jexactyl/commit/356a5b46a18d483ae90c862e130b1969e6df0777