Description
In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Published: 2026-08-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a Bouncy Castle keystore to accept a legacy BKS format that uses a 16‑bit integrity MAC key. This weak key strength permits an attacker to alter the keystore contents without detection, leading to a compromise of data integrity. The weakness is classified as CWE‑326, which denotes insufficient key generation strength.

Affected Systems

Affected products include Bouncy Castle Java libraries. Versions before 1.85 of the standard library and before 2.73.12 of the long‑term support library are vulnerable.

Risk and Exploitability

With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, which suggests moderate exploitation likelihood. The attack vector is inferred to be local or remote depending on whether an attacker can supply a malicious keystore file; no additional requirements are specified in the description.

Generated by OpenCVE AI on August 4, 2026 at 10:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Bouncy Castle Java 1.85 or newer, or to BC‑LTS 2.73.12 or later.
  • Configure the application to reject legacy BKS formats and require newer keystore formats.
  • Restrict filesystem permissions on keystore files and implement monitoring to detect unauthorized modifications.

Generated by OpenCVE AI on August 4, 2026 at 10:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:30:00 +0000


Mon, 03 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy version with 16-bit integrity MAC key. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
Title BKS keystore accepts legacy version with 16-bit integrity MAC key
Weaknesses CWE-326
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-java Bc-lts-java
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-08-03T13:31:42.030Z

Reserved: 2026-07-06T07:09:01.524Z

Link: CVE-2026-59651

cve-icon Vulnrichment

Updated: 2026-08-03T13:31:38.745Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-03T01:16:45.380

Modified: 2026-08-04T14:50:12.360

Link: CVE-2026-59651

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:00:07Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength