CVE-2026-86203: Pmmp Pocketmine-Mp

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.

Affected products

  • Pmmp Pocketmine-Mp: before 5.39.2 (fixed in 5.39.2)

Published 2026-09-09. Last modified 2026-10-08.