CVE-2026-107852
Received Received - Intake

Authentication Bypass via Stripe Payment Manipulation in Jexactyl

Vulnerability report for CVE-2026-107852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency. On an instance where the billing module is enabled and a Stripe secret key is configured, an authenticated client can therefore complete a lower-value or mismatched-currency payment and cause the order to be processed, provisioning, renewing, upgrading, or unsuspending the purchased server for less than the required price. This issue is fixed in version 4.0.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Jexactyl Jexactyl < 4.0.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Jexactyl is a game management panel with billing features. A vulnerability exists in versions before 4.0.5 where the POST /api/client/billing/stripe/process endpoint does not verify the payment amount or currency against the order details. An authenticated user can exploit this to pay less than required and still provision or modify servers.

Impact Analysis

If you use Jexactyl with billing enabled and Stripe configured, an attacker could pay less than the actual order value and still receive server resources. This could lead to financial loss for the service provider or unauthorized server access.

Mitigation Strategies

Upgrade Jexactyl to version 4.0.5 or later to address the vulnerability. Ensure the billing module is properly configured and Stripe secret keys are validated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart