Authentication Bypass Vulnerability in PocketMine-MP by PocketMine Team
CVE-2022-51016

5.3MEDIUM

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
7 September 2026

What is CVE-2022-51016?

The PocketMine-MP server software for Minecraft, versions 3.x prior to 3.27.0, lacks proper encryption for the Minecraft Bedrock protocol, leading to the potential for an authentication bypass. Attackers can exploit this vulnerability by capturing a valid login token from a player's session. By tricking the player into connecting to a malicious server, the attacker can impersonate the victim and maintain unauthorized access to XBOX Live functionalities until the token expires. This vulnerability primarily impacts servers accessible over the internet without encryption or proxy protection. The issue has been resolved in version 4.0.0 and backported to 3.27.0.

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.