Security Flaw in MintyItanium Lost-Auction Auction Plugin for Minecraft
CVE-2026-55624

5.3MEDIUM

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55624?

The MintyItanium Lost-Auction auction plugin for Minecraft contains a vulnerability that allows unauthorized item duplication and manipulation. Players were able to exploit this flaw to take items, such as barrier blocks, directly from the graphical user interface (GUI). This issue was resolved in commit 88c920b05042929db334ba06d57f052b42d6b3f8, but prior versions remain susceptible to this exploit, warranting immediate attention from users to ensure their game integrity.

Affected Version(s)

Lost-Auction < 88c920b05042929db334ba06d57f052b42d6b3f8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.