CVE-2026-86202
CVE-2026-86202 is a medium-severity vulnerability with a CVSS 3.x base score of 4.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-406.
Key facts
- Severity: Medium (CVSS 3.x base score 4.3)
- CVSS v4: 5.3
- EPSS exploit prediction: 0% (27th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-406
- Published:
- Last modified:
Description
PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
Frequently asked questions
- What is CVE-2026-86202?
- PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
- How severe is CVE-2026-86202?
- CVE-2026-86202 has a CVSS 3.x base score of 4.3, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2026-86202 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-86202?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86202 published?
- CVE-2026-86202 was published on 2026-09-09.
References
- https://github.com/pmmp/PocketMine-MP/commit/aeea1150a772a005b92bd418366f1b7cf1a91ab5
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-7hmv-4j2j-pp6f
- https://www.vulncheck.com/advisories/pocketmine-mp-before-5.39.2-network-amplification-via-actoreventpacket
Other CWE-406 vulnerabilities
- CVE-2021-38135 — High (CVSS 8.6): Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.
- CVE-2022-0028 — High (CVSS 8.6): A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified…
- CVE-2021-38487 — High (CVSS 8.2): RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an…
- CVE-2023-49203 — High (CVSS 7.5): Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb…
- CVE-2023-28456 — High (CVSS 7.5): An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times…
- CVE-2023-28455 — High (CVSS 7.5): An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop…