PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-51016 pmmp CVE debrief

CVE-2022-51016 is a vulnerability in PocketMine-MP 3.x before 3.27.0 that allows for impersonation via login replay attacks due to the lack of Minecraft Bedrock protocol encryption. This vulnerability affects servers directly reachable over the internet that are not behind a proxy with encryption enabled. The CVE record was published on 2026-09-07T13:17:23.607Z and has not been modified since then. Defenders of PocketMine-MP servers should assess exposure and prioritize updates or compensating controls. The vulnerability allows an attacker to capture a valid login from another player's session and replay it to impersonate the victim and pass XBOX Live authentication until the JWT

Vendor
pmmp
Product
PocketMine-MP
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders of PocketMine-MP servers, especially those directly reachable over the internet and not behind a proxy with encryption enabled, should assess exposure and prioritize updates or compensating controls.

Why it matters

CVE-2022-51016 allows for impersonation via login replay attacks in PocketMine-MP 3.x before 3.27.0 due to lack of Minecraft Bedrock protocol encryption. Defenders should prioritize verifying exposure, especially for servers directly reachable over the internet without encryption, and assess the need for updates or compensating controls.

  • Defenders need to verify exposure of PocketMine-MP servers to potential login replay attacks.
  • Servers directly reachable over the internet without encryption are at higher risk.
  • Impacts include potential impersonation of victims and bypass of XBOX Live authentication.
  • Remediation priority is high for servers not behind a proxy with encryption enabled.

Technical summary

PocketMine-MP 3.x before 3.27.0 does not implement Minecraft Bedrock protocol encryption, allowing an attacker to capture a valid login from another player's session and replay it to impersonate the victim and pass XBOX Live authentication until the JWT token expires. This vulnerability affects servers directly reachable over the internet that are not behind a proxy with encryption enabled. The lack of encryption allows for login replay attacks, which can lead to impersonation of victims and bypass of XBOX Live authentication. Defenders should prioritize verifying exposure of PocketMine-MP servers directly reachable over the internet, especially those not behind a proxy with encryption enabled, and assess the

Defensive priority

Defenders should prioritize verifying exposure of PocketMine-MP servers directly reachable over the internet, especially those not behind a proxy with encryption enabled, and assess the need for updates or compensating controls.

Recommended defensive actions

  • Verify if PocketMine-MP servers are directly reachable over the internet and not behind a proxy with encryption enabled.
  • Assess the need for updates to PocketMine-MP 3.27.0 or 4.0.0.
  • Implement compensating controls such as encryption for servers not directly reachable over the internet.
  • Monitor for potential login replay attacks and implement additional security measures as needed.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in PocketMine-MP 3.x before 3.27.0, which allows for impersonation of victims via login replay attacks due to the lack of Minecraft Bedrock protocol encryption.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-51016 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-51016

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-51016 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-51016

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.