SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-86203

LOW · CVSS 3.7 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

PocketMine-MP versions prior to 5.39.2 are vulnerable to a race condition that allows attackers to exploit the handling of disconnecting players, potentially leading to the duplication of inventory items and experience points. While the severity is rated low, developers and server administrators using affected versions should prioritize patching to prevent potential exploitation in multiplayer environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit poc

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86203
Severity
LOW
CVSS
3.7
EPSS
0.27%

Original NVD Description

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.