PatchSiren cyber security CVE debrief
CVE-2026-107854 Jexactyl CVE debrief
CVE-2026-107854 is a vulnerability in Jexactyl, a customizable game management panel and billing system. From version 4.0.0 to 4.0.4, an authenticated user can renew or unsuspend another tenant's billable server via the POST /api/client/billing/free/process endpoint, which lacks an ownership check. The issue arises because the endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. This allows unauthorized server renewal or unsuspension when the server's renewal_date is non-null and more than seven days away. The vulnerability is fixed in version 4.0.5. Defenders managing Jexactyl with billing
- Vendor
- Jexactyl
- Product
- Unknown
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders managing Jexactyl installations with billing enabled should assess exposure and verify server ownership checks to prevent unauthorized server renewal or unsuspension. This includes reviewing the current version and updating to 4.0.5 or later if necessary. Additionally, defenders should monitor for suspicious activity on billable servers and review compensating controls for exposed systems. Security teams and operators managing Jexactyl should be
Why it matters
CVE-2026-107854 allows authenticated users to renew or unsuspend arbitrary servers by ID in Jexactyl installations with billing enabled. Defenders should verify server ownership checks and update to version 4.0.5 or later to prevent potential exploitation.
- Potential unauthorized server renewal or unsuspension
- Possible lateral movement or privilege escalation
- Required verification of server ownership checks
- Necessity for timely patching to prevent exploitation
Technical summary
The POST /api/client/billing/free/process endpoint in Jexactyl accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. This allows an authenticated user to renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away. The vulnerability is caused by a missing ownership check in the endpoint, which enables unauthorized server renewal or unsuspension. The issue is fixed in version 4.0.5,
Defensive priority
Defenders should prioritize verifying server ownership checks in Jexactyl installations with billing enabled, especially for authenticated users.
Recommended defensive actions
- Verify server ownership checks in Jexactyl installations with billing enabled
- Update to version 4.0.5 or later
- Monitor for suspicious activity on billable servers
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed version. However, there is limited information on potential exploitation or victim impact. The source references confirm the vulnerability details and provide additional context. To verify the vulnerability, defenders should review the official advisory and CVE record. The lack of ownership checks in the free-billing order endpoint allows for potential unauthorized actions on billable servers. There are no known reports of exploitation,
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Jexactyl: Free-billing order endpoint renews and unsuspends arbitrary servers by ID (missing own
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107854.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-9xwv-p7r5-5h5p
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/commit/356a5b46a18d483ae90c862e130b1969e6df0777
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.