PatchSiren

Jexactyl CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Jexactyl CVE published 2026-10-09

CVE-2026-107854

CVE-2026-107854 is a vulnerability in Jexactyl, a customizable game management panel and billing system. From version 4.0.0 to 4.0.4, an authenticated user can renew or unsuspend another tenant's billable server via the POST /api/client/billing/free/process endpoint, which lacks an ownership check. The issue arises because the endpoint accepts a client-controlled server_id and loads the server without res [truncated]

HIGH Jexactyl CVE published 2026-10-09

CVE-2026-107852

CVE-2026-107852: Jexactyl Stripe payment forgery vulnerability allows authenticated clients to complete lower-value or mismatched-currency payments, provisioning servers for less than the required price. Fixed in version 4.0.5. The vulnerability exists in the billing system where the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is p [truncated]