CVE-2026-86203
Deferred Deferred - Pending Action

PocketMine-MP Race Condition Leads to Inventory Duplication

Vulnerability report for CVE-2026-86203, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pocketmine mp to 5.39.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-664 The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PocketMine-MP versions before 5.39.2 fail to validate if a player entity is despawned when processing attack packets. Attackers exploit a race condition by attacking a disconnecting player, causing multiple death handlers to trigger. This duplicates inventory items and experience as they drop multiple times.

Detection Guidance

Detecting this vulnerability requires monitoring for unusual item duplication events in PocketMine-MP servers. Check server logs for multiple death handler executions for the same player within a short timeframe. Look for inventory drops or experience duplication reports from players. No specific commands are provided in the resources, but server administrators should review logs for patterns matching the described race condition during player disconnections.

Impact Analysis

An attacker could duplicate valuable items or experience points in your inventory by exploiting this during disconnection. This could lead to loss of progress or unfair advantages in gameplay.

Compliance Impact

This vulnerability primarily impacts data integrity by allowing duplication of inventory items and experience points through a race condition exploit. While it does not directly expose or leak sensitive data, the duplication of items could potentially lead to unauthorized data manipulation or loss of audit trail integrity in systems handling regulated data. However, the vulnerability's scope is limited to game mechanics and does not directly interact with personal or health data typically covered by GDPR or HIPAA.

Mitigation Strategies
  • Upgrade PocketMine-MP to version 5.39.2 or later to apply the official patch.
  • If upgrading is not immediately possible, implement a plugin-based mitigation by handling the EntityDamageByEntityEvent and canceling it if the victim is flagged for despawn.
  • Monitor server logs for signs of exploitation attempts, particularly during player disconnections.
  • Temporarily restrict server access or disable vulnerable features if the issue persists until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86203. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart