Description
MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue.
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized item acquisition via GUI manipulation
Action: Apply patch
AI Analysis

Impact

The vulnerability in the MintyItanium Lost-Auction plugin allows a player to manipulate the in‑game search GUI to retrieve items such as barrier blocks or duplicate existing items. This flaw effectively bypasses the intended item restriction controls, enabling players to gain items they should not possess. The weakness is a form of incorrect authorization, leading to unauthorized data modification within the game environment.

Affected Systems

Any Minecraft server running the MintyItanium Lost-Auction plugin before the commit identified by 88c920b05042929db334ba06d57f052b42d6b3f8 is affected. The plugin is released by MintyItanium under the Lost-Auction label.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and there is no EPSS score available, suggesting limited publicly known exploitation activity. The issue was listed as not in the CISA KEV catalog. Attackers can exploit the flaw by simply engaging the GUI on a server that has not applied the recent patch; no external network vector is required.

Generated by OpenCVE AI on August 25, 2026 at 16:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Lost-Auction plugin to commit 88c920b05042929db334ba06d57f052b42d6b3f8 or newer.
  • If an update cannot be applied immediately, temporarily disable the auction functionality or the plugin entirely to prevent exploitation.
  • Review the plugin’s GUI handling code to ensure that proper authorization checks are in place for all item retrieval operations.

Generated by OpenCVE AI on August 25, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mintyitanium
Mintyitanium lost-auction
Vendors & Products Mintyitanium
Mintyitanium lost-auction

Tue, 25 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Description MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue.
Title MintyItanium Lost-Auction takes items like barrier blocks out from search GUI
Weaknesses CWE-670
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mintyitanium Lost-auction
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-25T18:27:35.700Z

Reserved: 2026-06-16T23:31:22.446Z

Link: CVE-2026-55624

cve-icon Vulnrichment

Updated: 2026-08-25T18:27:32.242Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T15:16:35.033

Modified: 2026-09-09T21:07:31.353

Link: CVE-2026-55624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:37:02Z

Weaknesses
  • CWE-670

    Always-Incorrect Control Flow Implementation