CVE-2026-107854 | Jexactyl up to 4.0.4 Billing process server_id privileges management
A vulnerability marked as critical has been reported in Jexactyl up to 4.0.4. This impacts an unknown function of the file /api/client/billing/free/process of the component Billing. Performing a manipulation of the argument server_id results in improper privilege management.
This vulnerability is reported as CVE-2026-107854. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More