PT-2026-104569 · Unknown · Bouncy Castle For Java

·

CVE-2026-71890

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber
Name of the Vulnerable Software and Affected Versions Bouncy Castle for Java versions prior to 1.86
Description Validation of an MLS (RFC 9420) external commit's proposal list in the validateExternalCachedProposals() function of org.bouncycastle.mls.protocol.Group failed to verify that a removed leaf was associated with the joiner. While RFC 9420 allows a joiner to remove an old version of themselves via a Remove proposal, the implementation did not ensure the LeafNode met the necessary credential criteria for the removed participant. Consequently, any party with the group's public GroupInfo could submit a Remove proposal specifying any member's LeafIndex, allowing them to evict that member and occupy their slot in the ratchet tree. This issue affected callers of the Group.externalJoin and Group.handle APIs, as the required credential check was only present in the gRPC interop harness.
Recommendations Update Bouncy Castle for Java to version 1.86 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71890

Affected Products

Bouncy Castle For Java