CVE-2026-71890: CWE-863 Incorrect Authorization in Legion of the Bouncy Castle Inc. BC-JAVA
CVE-2026-71890 is a high-severity authorization vulnerability in Bouncy Castle for Java versions 1.73 up to but not including 1.86. It involves improper validation of MLS external commit proposal lists, allowing an attacker with access to the group's public GroupInfo to remove any member from the group and take over their slot. The vulnerability arises because the validation did not verify that the removed leaf corresponded to the joiner, enabling unauthorized removal and replacement. The flaw was fixed by enforcing that an external commit carrying a Remove proposal is accepted only when the removed leaf's credential matches the joiner's new leaf credential on both sender and receiver sides.
AI Analysis
Technical Summary
In Bouncy Castle for Java before version 1.86, the method org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals failed to properly validate the relationship between the removed leaf in an MLS external commit and the joiner. RFC 9420 section 12.2 allows at most one Remove proposal in an external commit, which must remove an old version of the joiner and requires credential checks on the removed leaf. The existing validation counted proposals and bounded the removed leaf index but did not verify that the removed leaf belonged to the joiner. This omission allowed any party with the group's public GroupInfo to submit an external commit that removes any member by LeafIndex, causing all members to apply the removal and allowing the attacker to take over that member's slot in the ratchet tree. The credential check that should have prevented this was only present in the gRPC interop harness, leaving other API callers unprotected. The fix requires that an external commit with a Remove proposal is accepted only if the removed leaf's credential matches the joiner's new leaf credential on both sending and receiving sides.
Potential Impact
An attacker with access to the group's public GroupInfo can craft an external commit that removes any group member by LeafIndex, causing all members to evict that member and allowing the attacker to take over their slot in the ratchet tree. This compromises group membership integrity and could lead to unauthorized access or disruption of group communication. The vulnerability affects confidentiality and integrity of MLS group operations.
Mitigation Recommendations
Upgrade Bouncy Castle for Java to version 1.86 or later, where the vulnerability is fixed by enforcing credential checks on removed leaves in external commits. Until upgraded, be aware that the public GroupInfo can be used to perform unauthorized removals via external commits. No other mitigations are specified. Patch status is confirmed fixed in version 1.86.
CVE-2026-71890: CWE-863 Incorrect Authorization in Legion of the Bouncy Castle Inc. BC-JAVA
Description
CVE-2026-71890 is a high-severity authorization vulnerability in Bouncy Castle for Java versions 1.73 up to but not including 1.86. It involves improper validation of MLS external commit proposal lists, allowing an attacker with access to the group's public GroupInfo to remove any member from the group and take over their slot. The vulnerability arises because the validation did not verify that the removed leaf corresponded to the joiner, enabling unauthorized removal and replacement. The flaw was fixed by enforcing that an external commit carrying a Remove proposal is accepted only when the removed leaf's credential matches the joiner's new leaf credential on both sender and receiver sides.
CVSS v4.0
Score 8.7high
Affected software
Legion of the Bouncy Castle Inc.
BC-JAVA
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Bouncy Castle for Java before version 1.86, the method org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals failed to properly validate the relationship between the removed leaf in an MLS external commit and the joiner. RFC 9420 section 12.2 allows at most one Remove proposal in an external commit, which must remove an old version of the joiner and requires credential checks on the removed leaf. The existing validation counted proposals and bounded the removed leaf index but did not verify that the removed leaf belonged to the joiner. This omission allowed any party with the group's public GroupInfo to submit an external commit that removes any member by LeafIndex, causing all members to apply the removal and allowing the attacker to take over that member's slot in the ratchet tree. The credential check that should have prevented this was only present in the gRPC interop harness, leaving other API callers unprotected. The fix requires that an external commit with a Remove proposal is accepted only if the removed leaf's credential matches the joiner's new leaf credential on both sending and receiving sides.
Potential Impact
An attacker with access to the group's public GroupInfo can craft an external commit that removes any group member by LeafIndex, causing all members to evict that member and allowing the attacker to take over their slot in the ratchet tree. This compromises group membership integrity and could lead to unauthorized access or disruption of group communication. The vulnerability affects confidentiality and integrity of MLS group operations.
Mitigation Recommendations
Upgrade Bouncy Castle for Java to version 1.86 or later, where the vulnerability is fixed by enforcing credential checks on removed leaves in external commits. Until upgraded, be aware that the public GroupInfo can be used to perform unauthorized removals via external commits. No other mitigations are specified. Patch status is confirmed fixed in version 1.86.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- bcorg
- Date Reserved
- 2026-08-08T00:06:07.401Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac11721a43b0b3b89cacf55
Added to database: 10/03/2026, 14:54:25 UTC
Last enriched: 10/03/2026, 14:55:19 UTC
Last updated: 10/04/2026, 05:45:56 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.