CVE-2026-107854

CVE-2026-107854 published: Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the...

View full NVD advisory → ← Back to CVE watch