Description
Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.
Published: 2026-10-09
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Server Renewal and Unsuspension
Action: Patch Immediately
AI Analysis

Impact

A misconfigured POST endpoint in Jexactyl accepts a client-supplied server identifier and loads any server the user can specify, without checking ownership. An authenticated user can therefore renew or unsuspend any other tenant’s billable instance when the server’s renewal date is set and more than a week away. This flaw gives a non‑owner the ability to alter billing and service status for resources they do not own, potentially causing revenue loss and service interruptions. The weakness is an authorization bypass (CWE‑639).

Affected Systems

The vulnerability affects the Jexactyl panel from version 4.0.0 through and including 4.0.5. Users running any of these releases are susceptible unless mitigated by a patch or manual configuration changes.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate result, reflecting the need for attacker authentication but no need for additional privileges beyond normal user rights. Because the flaw permits privilege escalation across tenants, the impact is significant for multi‑tenant deployments. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, but the lack of an ownership check makes it a high‑impact risk for any organization running these affected Jexactyl versions.

Generated by OpenCVE AI on October 9, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Jexactyl to version 4.0.5 or later, which implements the ownership check to secure the free‑billing endpoint.
  • If an update is not immediately possible, disable the /api/client/billing/free/process endpoint or restrict it to authorized owner accounts using server‑side access controls.
  • Audit and configure subuser permissions to ensure only users with explicit ownership can access billing actions, and monitor logs for unauthorized renewal or unsuspension attempts.

Generated by OpenCVE AI on October 9, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jexactyl
Jexactyl jexactyl
Vendors & Products Jexactyl
Jexactyl jexactyl

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.
Title Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing ownership check)
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Jexactyl Jexactyl
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:31:02.541Z

Reserved: 2026-10-08T22:34:49.292Z

Link: CVE-2026-107854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:03.233

Modified: 2026-10-09T21:17:03.233

Link: CVE-2026-107854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key