THREAT OPS › Threat News › [NVD] CVE-2021-48006 (LOW 3.3) — PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoke
[NVD] CVE-2021-48006 (LOW 3.3) — PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoke
CVE-2021-48006 CVSS: 3.3 LOW Published: 2026-09-06T12:17:14.637
PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoked using the deop command, leaving the player as an oper
Indicators of compromise
- CVE-2021-48006cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-48006