Impact
A misconfigured POST endpoint in Jexactyl accepts a client-supplied server identifier and loads any server the user can specify, without checking ownership. An authenticated user can therefore renew or unsuspend any other tenant’s billable instance when the server’s renewal date is set and more than a week away. This flaw gives a non‑owner the ability to alter billing and service status for resources they do not own, potentially causing revenue loss and service interruptions. The weakness is an authorization bypass (CWE‑639).
Affected Systems
The vulnerability affects the Jexactyl panel from version 4.0.0 through and including 4.0.5. Users running any of these releases are susceptible unless mitigated by a patch or manual configuration changes.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate result, reflecting the need for attacker authentication but no need for additional privileges beyond normal user rights. Because the flaw permits privilege escalation across tenants, the impact is significant for multi‑tenant deployments. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but the lack of an ownership check makes it a high‑impact risk for any organization running these affected Jexactyl versions.
OpenCVE Enrichment