Skip to main content
EPSS 0.2%top 85%

CVE-2026-71890: CWE-863 Incorrect Authorization in Legion of the Bouncy Castle Inc. BC-JAVA

0
High
VulnerabilityCVE-2026-71890cvecve-2026-71890cwe-863
Published: 10/03/2026 (10/03/2026, 08:57:00 UTC)
Source: CVE Database V5
Vendor/Project: Legion of the Bouncy Castle Inc.
Product: BC-JAVA

Description

CVE-2026-71890 is a high-severity authorization vulnerability in Bouncy Castle for Java versions 1.73 up to but not including 1.86. It involves improper validation of MLS external commit proposal lists, allowing an attacker with access to the group's public GroupInfo to remove any member from the group and take over their slot. The vulnerability arises because the validation did not verify that the removed leaf corresponded to the joiner, enabling unauthorized removal and replacement. The flaw was fixed by enforcing that an external commit carrying a Remove proposal is accepted only when the removed leaf's credential matches the joiner's new leaf credential on both sender and receiver sides.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber

Affected software

Legion of the Bouncy Castle Inc.

BC-JAVA

Affected versions
>=1.73 <1.86
GitHub Actionsmore threats →cve
bcmls
pkg:github/bcmls
Affected versions
>=1.73 <1.86

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 14:55:19 UTC

Technical Analysis

In Bouncy Castle for Java before version 1.86, the method org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals failed to properly validate the relationship between the removed leaf in an MLS external commit and the joiner. RFC 9420 section 12.2 allows at most one Remove proposal in an external commit, which must remove an old version of the joiner and requires credential checks on the removed leaf. The existing validation counted proposals and bounded the removed leaf index but did not verify that the removed leaf belonged to the joiner. This omission allowed any party with the group's public GroupInfo to submit an external commit that removes any member by LeafIndex, causing all members to apply the removal and allowing the attacker to take over that member's slot in the ratchet tree. The credential check that should have prevented this was only present in the gRPC interop harness, leaving other API callers unprotected. The fix requires that an external commit with a Remove proposal is accepted only if the removed leaf's credential matches the joiner's new leaf credential on both sending and receiving sides.

Potential Impact

An attacker with access to the group's public GroupInfo can craft an external commit that removes any group member by LeafIndex, causing all members to evict that member and allowing the attacker to take over their slot in the ratchet tree. This compromises group membership integrity and could lead to unauthorized access or disruption of group communication. The vulnerability affects confidentiality and integrity of MLS group operations.

Mitigation Recommendations

Upgrade Bouncy Castle for Java to version 1.86 or later, where the vulnerability is fixed by enforcing credential checks on removed leaves in external commits. Until upgraded, be aware that the public GroupInfo can be used to perform unauthorized removals via external commits. No other mitigations are specified. Patch status is confirmed fixed in version 1.86.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
bcorg
Date Reserved
2026-08-08T00:06:07.401Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac11721a43b0b3b89cacf55

Added to database: 10/03/2026, 14:54:25 UTC

Last enriched: 10/03/2026, 14:55:19 UTC

Last updated: 10/04/2026, 05:45:56 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses