VYPR
Medium severity5.3NVD Advisory· Published Jun 2, 2026

CVE-2026-45289

CVE-2026-45289

Description

CloudburstMC Protocol library has a validation flaw in auth tokens, potentially impacting Minecraft Bedrock Edition servers prior to version 3.0.0.Beta12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CloudburstMC Protocol library has a validation flaw in auth tokens, potentially impacting Minecraft Bedrock Edition servers prior to version 3.0.0.Beta12.

Vulnerability

Prior to version 3.0.0.Beta12-20260420.182526-15, the CloudburstMC Protocol library for Minecraft Bedrock Edition has a partial missing validation for FULL type authentication tokens within its EncryptionUtils methods. This vulnerability affects publicly accessible software that depends on the affected versions of the Protocol library [1].

Exploitation

An attacker could exploit this vulnerability by sending specially crafted authentication payloads for FULL type tokens. The exact conditions and steps required for exploitation are not detailed in the available references, but it involves interacting with the EncryptionUtils methods that validate these tokens [1].

Impact

This vulnerability impacts publicly accessible software that relies on the affected versions of the CloudburstMC Protocol library. Successful exploitation could lead to unauthorized actions or data compromise, depending on how the affected software utilizes the validated authentication tokens [1].

Mitigation

The vulnerability has been patched in version 3.0.0.Beta12-20260420.182526-15 of the CloudburstMC Protocol library. Users should upgrade to this version or later. Geyser users should update to Build #1122 or later. A potential workaround involves adding further validation for the xid and xname fields for FULL type tokens [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.