CVE-2026-86199

PocketMine-MP versions before 5.43.1 fail to properly validate the Certificate field during offline login authentication. Unauthenticated players can trigger an uninitialized property access error that crashes the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-09 20:20


NVD link : CVE-2026-86199

Mitre link : CVE-2026-86199

CVE.ORG link : CVE-2026-86199


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs