CVE-2026-86199

Summary

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.

Affected Software

VendorProductVersion RangeStatus
pmmpPocketMine-MP0 < 5.43.1affected
pmmpPocketMine-MP5.43.1unaffected

Weaknesses

  • CWE-184: Incomplete List of Disallowed Inputs

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: partial

Additional References

References