CVE-2026-71885
Received Received - Intake

Bouncy Castle Java MLS X.509 Credential Validation Bypass

Vulnerability report for CVE-2026-71885, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
bouncy_castle bc_java to 1.86 (exc)
bouncy_castle bouncy_castle 1.86

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71885 is a vulnerability in Bouncy Castle for Java before version 1.86. It affects the Messaging Layer Security (MLS) implementation where X.509 credentials were not properly bound to LeafNode signature keys as required by RFC 9420. This allowed attackers to impersonate others by presenting a mismatched certificate and signature key pair. The flaw existed because the library did not validate that the end-entity certificate's public key matched the signature key in the LeafNode, enabling forged identities during group communications.

Detection Guidance

To detect this vulnerability, check if your Bouncy Castle Java library version is below 1.86. Use commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect the library version in your project. If using a JAR file, inspect the manifest or run 'java -jar your-application.jar' and check for errors during MLS operations.

Impact Analysis

An attacker could exploit this vulnerability to impersonate a legitimate user in a group communication system. This may lead to unauthorized access to group messages, eviction of valid members, decryption of current and future messages, and sending messages under the victim's identity. The impact depends on whether the system uses X.509 credentials and allows external commits without additional checks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. If exploited, it may result in data breaches, unauthorized disclosure of personal or health information, and failure to maintain data integrity. Compliance with these regulations requires ensuring secure communication channels and proper identity verification, which this flaw undermines.

Mitigation Strategies

Upgrade Bouncy Castle Java library to version 1.86 or later. Review MLS configurations to ensure X.509 credential binding is enforced. If using external commits, implement independent credential-admission checks to prevent impersonation. Monitor group membership and message integrity for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71885. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart