PT-2026-67245 · Unknown · Bouncy Castle For Java

CVE-2026-59652

·

Published

2026-08-03

·

Updated

2026-08-10

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/U:Amber
Name of the Vulnerable Software and Affected Versions Bouncy Castle for Java versions prior to 1.85
Description An LDAP filter injection issue exists in the legacy jdk1.4 LDAPStoreHelper class. LDAP filter injection occurs when an application fails to properly sanitize user-supplied input used to construct an LDAP filter, allowing an attacker to manipulate the query logic.
Recommendations Update Bouncy Castle for Java to version 1.85 or later. As a temporary mitigation, restrict the use of the LDAPStoreHelper class in legacy jdk1.4 environments.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59652
OPENSUSE-SU-2026:11445-1
OPENSUSE-SU-2026:21538-1
SUSE-SU-2026:23127-1
SUSE-SU-2026:23150-1
SUSE-SU-2026:3559-1

Affected Products

Bouncy Castle For Java