CVE-2026-86199
Deferred Deferred - Pending Action

Unauthenticated Server Crash in PocketMine-MP Due to Uninitialized Property

Vulnerability report for CVE-2026-86199, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
pocketmine mp to 5.43.1 (exc)
pocketmine mp 5.43.0
pocketmine mp 5.43.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-184 The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86199 is a vulnerability in PocketMine-MP versions before 5.43.1 where the server fails to validate the Certificate field during offline login authentication. This allows unauthenticated players to crash the server by triggering an uninitialized property access error.

Detection Guidance

Check PocketMine-MP server version with 'php -r "echo PocketMine\MP\VersionInfo::VERSION;". If it is below 5.43.1, the server is vulnerable. Monitor server logs for crashes during player login attempts without Xbox authentication.

Impact Analysis

This vulnerability allows unauthenticated players to remotely crash the server repeatedly without needing authentication. Public servers are particularly affected as they can be disrupted by attackers exploiting this flaw.

Compliance Impact

This vulnerability primarily causes server crashes due to improper authentication handling, which may lead to service disruptions. While it does not directly expose personal data, repeated crashes could impact availability of systems processing personal data, potentially affecting compliance with GDPR's availability principle (Article 32) or HIPAA's access controls (45 CFR Β§ 164.312). However, no evidence suggests this CVE directly violates these regulations.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.43.1 or later immediately. If upgrading is not possible, restrict network access to the server or disable offline login functionality until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86199. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart