Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107852— Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payment (payment forgery)

Quick assessment

Affected
Jexactyl Jexactyl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Jexactyl 是一款可定制的游戏管理面板和计费系统。在 4.0.5 版本之前,POST /api/client/billing/stripe/process 端点在接受客户端提供的 Stripe 结账会话时,即使支付状态(payment_status)为“已支付”,也不会将订单中的总金额(amount_total)和货币类型与订单引用及配置的计费货币进行比较。因此,在启用了计费模块并配置了 Stripe 密钥的实例上,经过身份验证的客户端可以完成金额更低或货币不匹配的支付,从而使订单被处理,并以低于所需价格的价

CVSS 7.1 · High EPSS 0.16% · P5

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Jexactyl Jexactyl < 4.0.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107852

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Jexactyl: Stripe checkout confirmation accepts mismatched-currency/amount payments as full payment (payment forgery)
Source: CVE Program / CVE List V5
Vulnerability Description
Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency. On an instance where the billing module is enabled and a Stripe secret key is configured, an authenticated client can therefore complete a lower-value or mismatched-currency payment and cause the order to be processed, provisioning, renewing, upgrading, or unsuspending the purchased server for less than the required price. This issue is fixed in version 4.0.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Jexactyl Jexactyl < 4.0.5 -

II. Public POCs for CVE-2026-107852

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107852

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107852 (1)

Vendor Advisories for CVE-2026-107852 (1)

Vendor Pages for CVE-2026-107852 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107852

No comments yet


Leave a comment