Description
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
Published: 2026-09-09
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Item Duplication via client disconnect
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows an attacker to trigger a race condition during client disconnection that causes the server to execute multiple death handlers. Each death handler causes the player's inventory items and experience to be dropped and subsequently re‑added, resulting in duplicate items and XP. The weakness is categorized as CWE‑664, an improper synchronization issue.

Affected Systems

All PocketMine‑MP installations running versions earlier than 5.39.2 are affected. This includes any server instance deployed by the pmmp community and any version before the 5.39.2 release on the official repository.

Risk and Exploitability

The CVSS score is 6.3, representing medium impact. No EPSS value is supplied, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Based on the description, it is inferred that the attack requires an attacker to control a client that connects to the server and send crafted packets during a disconnect event. Based on the description, it is inferred that given the symmetry of the attack vector, it can be performed over the public internet if the server allows arbitrary connections. Once triggered, the server will duplicate items and XP for the victim player without requiring administrator privileges.

Generated by OpenCVE AI on September 9, 2026 at 16:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PocketMine‑MP to version 5.39.2 or later to ensure proper despawn validation is implemented.
  • If an immediate upgrade is not possible, apply temporary rate limiting or packet filtering to reduce the chance of the race condition during disconnect events.
  • Continuously audit player inventories and experience levels for sudden or unexplained increases, and roll back or remove any duplicated items that are detected.

Generated by OpenCVE AI on September 9, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Pmmp
Pmmp pocketmine-mp
Vendors & Products Pmmp
Pmmp pocketmine-mp

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
Title PocketMine-MP before 5.39.2 Item Duplication via Despawn State
Weaknesses CWE-664
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Pmmp Pocketmine-mp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:58.125Z

Reserved: 2026-09-05T11:52:36.822Z

Link: CVE-2026-86203

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:47.443Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:21.550

Modified: 2026-09-10T15:17:50.307

Link: CVE-2026-86203

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:00:14Z

Weaknesses
  • CWE-664

    Improper Control of a Resource Through its Lifetime