5.4
CVE-2026-107854
- EPSS -
- Veröffentlicht 09.10.2026 20:31:02
- Zuletzt bearbeitet 09.10.2026 21:17:03
- Erkennungen
Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check)
Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerJexactyl
≫
Produkt
Jexactyl
Version
>= 4.0.0, < 4.0.5
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5
https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-9xwv-p7r5-5h5p
https://github.com/Jexactyl/Jexactyl/commit/356a5b46a18d483ae90c862e130b1969e6df0777