PatchSiren cyber security CVE debrief
CVE-2026-107852 Jexactyl CVE debrief
CVE-2026-107852: Jexactyl Stripe payment forgery vulnerability allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Fixed in version 4.0.5. The vulnerability exists in the billing system where the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency.
- Vendor
- Jexactyl
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess the impact of the vulnerability and take necessary actions to prevent exploitation.
Why it matters
CVE-2026-107852 allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch to prevent payment forgery and potential financial losses.
- Authenticated clients can provision servers for less than the required price.
- Payment forgery can lead to financial losses.
- Defenders must verify exposure and apply the patch to prevent exploitation.
- Remediation priority is high due to the potential for financial impact.
Technical summary
The Jexactyl billing system, prior to version 4.0.5, accepts client-supplied Stripe Checkout Sessions with mismatched currency or amount, allowing for payment forgery. This issue is fixed in version 4.0.5. The vulnerability allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch to prevent payment forgery and potential financial losses.
Defensive priority
Defenders should prioritize verifying exposure and applying the patch, as the vulnerability allows for payment forgery.
Recommended defensive actions
- Verify if the instance has the billing module enabled and a Stripe secret key configured.
- Check if the Jexactyl version is less than 4.0.5 and update to 4.0.5 if necessary.
- Monitor for suspicious payment activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed version. The vulnerability allows for payment forgery and potential financial losses. Defenders managing Jexactyl instances with the billing module enabled and Stripe configured should verify exposure and apply the patch. Evidence is limited to public CVE details and may not reflect all affected deployments or configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payme
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107852.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-rf56-676w-hj4g
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/commit/fdee722c560ac13dc2d26271912203a6085dffe3
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.