PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107854 Jexactyl CVE debrief

CVE-2026-107854 is a vulnerability in Jexactyl, a customizable game management panel and billing system. From version 4.0.0 to 4.0.4, an authenticated user can renew or unsuspend another tenant's billable server via the POST /api/client/billing/free/process endpoint, which lacks an ownership check. The issue arises because the endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. This allows unauthorized server renewal or unsuspension when the server's renewal_date is non-null and more than seven days away. The vulnerability is fixed in version 4.0.5. Defenders managing Jexactyl with billing

Vendor
Jexactyl
Product
Unknown
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders managing Jexactyl installations with billing enabled should assess exposure and verify server ownership checks to prevent unauthorized server renewal or unsuspension. This includes reviewing the current version and updating to 4.0.5 or later if necessary. Additionally, defenders should monitor for suspicious activity on billable servers and review compensating controls for exposed systems. Security teams and operators managing Jexactyl should be

Why it matters

CVE-2026-107854 allows authenticated users to renew or unsuspend arbitrary servers by ID in Jexactyl installations with billing enabled. Defenders should verify server ownership checks and update to version 4.0.5 or later to prevent potential exploitation.

  • Potential unauthorized server renewal or unsuspension
  • Possible lateral movement or privilege escalation
  • Required verification of server ownership checks
  • Necessity for timely patching to prevent exploitation

Technical summary

The POST /api/client/billing/free/process endpoint in Jexactyl accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. This allows an authenticated user to renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away. The vulnerability is caused by a missing ownership check in the endpoint, which enables unauthorized server renewal or unsuspension. The issue is fixed in version 4.0.5,

Defensive priority

Defenders should prioritize verifying server ownership checks in Jexactyl installations with billing enabled, especially for authenticated users.

Recommended defensive actions

  • Verify server ownership checks in Jexactyl installations with billing enabled
  • Update to version 4.0.5 or later
  • Monitor for suspicious activity on billable servers
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed version. However, there is limited information on potential exploitation or victim impact. The source references confirm the vulnerability details and provide additional context. To verify the vulnerability, defenders should review the official advisory and CVE record. The lack of ownership checks in the free-billing order endpoint allows for potential unauthorized actions on billable servers. There are no known reports of exploitation,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107854 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107854

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107854 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107854

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing own

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107854.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-9xwv-p7r5-5h5p

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/commit/356a5b46a18d483ae90c862e130b1969e6df0777

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.