๐Ÿ” CVE Alert

CVE-2022-51016

MEDIUM 6.1

PocketMine-MP 3.x before 3.27.0 Authentication Bypass via Login Replay

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid login from another player's session (for example by tricking the player into connecting to an attacker-controlled server) can replay that login to impersonate the victim and pass XBOX Live authentication until the JWT token expires (typically 2-3 days). This affects servers directly reachable over the internet that are not behind a proxy with encryption enabled. Fixed in 4.0.0 and backported to 3.27.0.

CWE CWE-294
Vendor pmmp
Product pocketmine-mp
Published Sep 7, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for pmmp pocketmine-mp

Be the first to know when new medium vulnerabilities affecting pmmp pocketmine-mp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

pmmp / PocketMine-MP
3.0.0 < 3.27.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-h79x-98r2-g6qc github.com: https://github.com/pmmp/PocketMine-MP/commit/d28be4eaf24a890f7ef110a51181a3d806a6acca vulncheck.com: https://www.vulncheck.com/advisories/pocketmine-mp-before-4.0.0-authentication-bypass-via-login-replay