Entity Despawn Vulnerability in PocketMine-MP by PocketMine
CVE-2026-86203

6.3MEDIUM

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
9 September 2026

What is CVE-2026-86203?

PocketMine-MP versions prior to 5.39.2 are susceptible to a flaw that fails to properly validate the despawn state of entities when processing attack packets received from clients. This oversight allows attackers to exploit a race condition by targeting players who are disconnecting. As a result, multiple death handlers can be triggered, leading to repeated drops of inventory items and experience, enabling item duplication. Users are advised to upgrade to version 5.39.2 or higher to mitigate this vulnerability.

Affected Version(s)

PocketMine-MP 0 < 5.39.2

PocketMine-MP 5.39.2

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kostamax27
dktapps
.