In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any… (CVE-2026-71886)
A vulnerability in Bouncy Castle for Java before version 1.86 allows the OpenPGP certificate API to accept third-party certifications or trust delegations from subkeys that lack proper certification authority flags. This flaw permits a restricted subkey, such as one intended only for signing data, to issue valid User ID certifications or trust delegations, effectively elevating its authority improperly. The vulnerability does not compromise the primary key or private keys but undermines the intended separation of certification capabilities within key components.
AI Analysis
Technical Summary
In Bouncy Castle for Java versions prior to 1.86, the OpenPGP certificate API's methods getCertificationBy() and getDelegationBy() accepted third-party signatures from any component key of the issuing certificate without verifying that the component held the RFC 9580 section 5.2.3.29 CERTIFY_OTHER key flag at the time of signature creation. This allowed subkeys bound only for signing or encryption (which can also sign) to issue valid User ID certifications or direct-key trust delegations, which the API treated as valid and attributed to the issuing certificate. The vulnerability does not forge the primary key's signature or expose private keys but allows an attacker-controlled subkey to gain certification authority improperly. The fix requires that third-party certifications or delegations be accepted only if the signing component is the primary key or a subkey with the CERTIFY_OTHER flag at signature creation.
Potential Impact
The vulnerability enables an attacker controlling a restricted subkey to issue valid certifications or trust delegations that the API accepts as legitimate, effectively elevating the subkey's authority to that of the primary key's identity-issuing capability. This undermines the containment intended by key flag separation, potentially allowing unauthorized trust assertions. However, it does not compromise the primary key's private key or forge its signature. There are no known exploits in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, applications should be cautious in treating getCertificationBy(...).isValid() or getDelegationBy(...) results as definitive trust or identity decisions without additional validation of key flags.
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API accepted a third-party certification or trust delegation from any… (CVE-2026-71886)
Description
A vulnerability in Bouncy Castle for Java before version 1.86 allows the OpenPGP certificate API to accept third-party certifications or trust delegations from subkeys that lack proper certification authority flags. This flaw permits a restricted subkey, such as one intended only for signing data, to issue valid User ID certifications or trust delegations, effectively elevating its authority improperly. The vulnerability does not compromise the primary key or private keys but undermines the intended separation of certification capabilities within key components.
CVSS v4.0
Affected software
pkg:maven/org.bouncycastle/bcprov-jdk15onRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Bouncy Castle for Java versions prior to 1.86, the OpenPGP certificate API's methods getCertificationBy() and getDelegationBy() accepted third-party signatures from any component key of the issuing certificate without verifying that the component held the RFC 9580 section 5.2.3.29 CERTIFY_OTHER key flag at the time of signature creation. This allowed subkeys bound only for signing or encryption (which can also sign) to issue valid User ID certifications or direct-key trust delegations, which the API treated as valid and attributed to the issuing certificate. The vulnerability does not forge the primary key's signature or expose private keys but allows an attacker-controlled subkey to gain certification authority improperly. The fix requires that third-party certifications or delegations be accepted only if the signing component is the primary key or a subkey with the CERTIFY_OTHER flag at signature creation.
Potential Impact
The vulnerability enables an attacker controlling a restricted subkey to issue valid certifications or trust delegations that the API accepts as legitimate, effectively elevating the subkey's authority to that of the primary key's identity-issuing capability. This undermines the containment intended by key flag separation, potentially allowing unauthorized trust assertions. However, it does not compromise the primary key's private key or forge its signature. There are no known exploits in the wild.
Mitigation Recommendations
No official patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is applied, applications should be cautious in treating getCertificationBy(...).isValid() or getDelegationBy(...) results as definitive trust or identity decisions without additional validation of key flags.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-7hrr-mw36-px4x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71886"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac1397da43b0b3b89d66c8b
Added to database: 10/03/2026, 17:21:01 UTC
Last enriched: 10/03/2026, 17:30:47 UTC
Last updated: 10/04/2026, 02:46:06 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.