CVE-2026-71886
Received Received - Intake

OpenPGP Certificate Authority Bypass in Bouncy Castle Java

Vulnerability report for CVE-2026-71886, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: bcorg

Description

In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. OpenPGPCertificate.getCertificationBy() and getDelegationBy() resolve a third-party signature by matching its issuer key identifier against every key of the third-party certificate, then verify the issuing component's binding chain and the signature itself; nothing checked that the issuing component carried the RFC 9580 sec. 5.2.3.29 certification key flag (CERTIFY_OTHER) when the signature was created. A subkey bound only with SIGN_DATA - the online signing subkey of exactly the offline-primary arrangement those key flags exist to express - could therefore issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust, and the API returned it as a valid signature chain attributed to the third-party certificate. An application treating getCertificationBy(...).isValid() or getDelegationBy(...) as an identity or trusted-introducer decision would attribute the attacker's assertion to the offline primary key. The same held for a legacy RSA subkey bound only for encryption, whose algorithm is nonetheless able to sign. This does not forge the primary key's signature or recover any private key; it promotes an already-compromised restricted subkey to the primary key's identity-issuing authority, defeating the containment the key-flag separation provides. A third-party certification or delegation is now attributed to the issuing certificate only when the component key that made it is the primary key, or is a subkey holding CERTIFY_OTHER when the signature was created, so certification-capable subkeys continue to be accepted; primary keys are accepted whatever their key flags say, since a primary key is certification-capable by construction and certificates carrying no key flags subpacket at all are common. Third-party revocations are deliberately outside the rule, since declining to honour one would keep trust alive rather than withdraw it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
bcgit bc-java to 1.86 (exc)
bcgit bc-java From 1.81 (inc) to 1.86 (exc)
bouncy_castle bouncy_castle 1.86

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71886 is a flaw in Bouncy Castle for Java before version 1.86 affecting OpenPGP certificate handling. It allows subkeys without the required CERTIFY_OTHER flag to issue valid certifications or trust delegations, bypassing the intended separation between primary and subkeys. This lets an attacker misuse a compromised subkey to certify identities or trust levels attributed to the primary key.

Detection Guidance

To detect this vulnerability, check the version of Bouncy Castle Java library in use. If your system uses versions before 1.86, it is vulnerable. Commands like 'mvn dependency:tree' for Maven projects or inspecting the library files directly can help identify the version.

Impact Analysis

Applications using Bouncy Castle's OpenPGP API methods like getCertificationBy() or getDelegationBy() for identity or trust decisions could be misled. An attacker could exploit this to attribute false certifications or delegations to the primary key, potentially granting unauthorized trust or identity claims. This does not recover private keys but defeats the containment provided by key-flag separation.

Compliance Impact

This vulnerability could undermine compliance with standards like GDPR and HIPAA by allowing attackers to forge identity certifications or trust delegations in OpenPGP certificates. Applications relying on Bouncy Castle's OpenPGP API for identity verification or trust decisions might incorrectly attribute malicious certifications to legitimate primary keys, potentially enabling unauthorized access or data breaches.

Mitigation Strategies

Upgrade Bouncy Castle Java library to version 1.86 or later immediately. Review applications using OpenPGP certificate APIs, particularly methods like getCertificationBy() or getDelegationBy(), to ensure they handle key certification capabilities correctly after the update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71886. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart