CVE-2026-86203 Details
Description
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
A vulnerability in PocketMine-MP versions prior to 5.39.2 allows for improper validation of entity despawn states when handling attack packets from clients. This issue creates a race condition where an attacker can target a player who is disconnecting, causing multiple death handlers to trigger. As a result, inventory items and experience are dropped multiple times, leading to duplication.
Users can update to PocketMine-MP version 5.39.2 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-664 | Improper Control of a Resource Through its Lifetime | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PocketMine-MP | < 5.39.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion