PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107852 Jexactyl CVE debrief

CVE-2026-107852: Jexactyl Stripe payment forgery vulnerability allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Fixed in version 4.0.5. The vulnerability exists in the billing system where the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency.

Vendor
Jexactyl
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of the vulnerability and take necessary actions to prevent exploitation.

Why it matters

CVE-2026-107852 allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch to prevent payment forgery and potential financial losses.

  • Authenticated clients can provision servers for less than the required price.
  • Payment forgery can lead to financial losses.
  • Defenders must verify exposure and apply the patch to prevent exploitation.
  • Remediation priority is high due to the potential for financial impact.

Technical summary

The Jexactyl billing system, prior to version 4.0.5, accepts client-supplied Stripe Checkout Sessions with mismatched currency or amount, allowing for payment forgery. This issue is fixed in version 4.0.5. The vulnerability allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch to prevent payment forgery and potential financial losses.

Defensive priority

Defenders should prioritize verifying exposure and applying the patch, as the vulnerability allows for payment forgery.

Recommended defensive actions

  • Verify if the instance has the billing module enabled and a Stripe secret key configured.
  • Check if the Jexactyl version is less than 4.0.5 and update to 4.0.5 if necessary.
  • Monitor for suspicious payment activity.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed version. The vulnerability allows for payment forgery and potential financial losses. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch. Evidence is limited to public CVE details and may not reflect all affected deployments or configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107852 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107852

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107852 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107852

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payme

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107852.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-rf56-676w-hj4g

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/commit/fdee722c560ac13dc2d26271912203a6085dffe3

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.