PT-2026-86514 · Unknown · Pocketmine-Mp

CVE-2021-48006

·

Published

2021-12-16

·

Updated

2026-09-06

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions PocketMine-MP versions prior to 4.0.3
Description The removeOp() function fails to perform case-insensitive matching when removing operator entries from the ops.txt file. While the function converts the supplied name to lowercase, it only removes entries that are an exact match. Consequently, if an operator name contains uppercase letters, the deop command cannot revoke their privileges, requiring the entry to be deleted manually from the file.
Recommendations Update to version 4.0.3 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-48006
GHSA-J5QG-W9JG-3WG3

Affected Products

Pocketmine-Mp