Description
Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to have a forged X.509 attribute certificate accepted as valid, and so obtain whatever roles or privileges an application grants on the strength of its attributes, via an attribute certificate that names a trusted attribute authority as its issuer but was not signed by it, because the RFC 3281 validation steps check the holder and issuer certification paths, validity period, extensions and revocation status but never verify the attribute certificate's signature with the issuer's public key. Only applications that use these classes to validate attribute certificates are affected.
Published: 2026-10-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

Recently released information shows that a flaw in the attribute certificate path validator of Bouncy Castle’s bc‑csharp library allows a remote attacker to create a forged X.509 attribute certificate that passes all correctness checks—apart from the actual signature verification step. Because the validator does not confirm that the certificate’s signature matches the issuer’s public key, an attacker can inject arbitrary attributes or roles into an application. This enables the attacker to receive any privileges or access rights the application grants based on those attributes, effectively escalating their permissions within the affected system.

Affected Systems

The vulnerability affects the bc‑csharp library from Bouncy Castle, specifically versions prior to 2.7.0. Only applications that explicitly invoke the PkixAttrCertPathValidator or PkixAttrCertPathBuilder classes for processing attribute certificates are impacted. Users should verify whether their code performs such validation and whether any earlier versions of bc‑csharp are in use.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity overall, while the EPSS score is not publicly available, so an exact likelihood of exploitation cannot be estimated. The issue is not listed in the CISA KEV catalog, suggesting that there is no documented exploitation of this specific flaw at the time of analysis. Nevertheless, the flaw can be exploited remotely by supplying a forged attribute certificate to an application that trusts the library for validation. Breaches would most likely arise from malicious input or compromised configuration that allows untrusted certificates to be processed, resulting in an unauthorized elevation of privileges.

Generated by OpenCVE AI on October 2, 2026 at 08:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to bc‑csharp version 2.7.0 or later
  • Ensure that applications enforce verification of the attribute certificate’s signature before accepting any granted attributes
  • Limit trust to known, authorized attribute authorities and monitor the issuance of attribute certificates for anomalies

Generated by OpenCVE AI on October 2, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker to have a forged X.509 attribute certificate accepted as valid, and so obtain whatever roles or privileges an application grants on the strength of its attributes, via an attribute certificate that names a trusted attribute authority as its issuer but was not signed by it, because the RFC 3281 validation steps check the holder and issuer certification paths, validity period, extensions and revocation status but never verify the attribute certificate's signature with the issuer's public key. Only applications that use these classes to validate attribute certificates are affected.
Title Attribute certificate path validation does not verify the attribute certificate's signature
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-02T07:04:17.323Z

Reserved: 2026-07-16T23:50:45.118Z

Link: CVE-2026-63571

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T08:17:01.993

Modified: 2026-10-02T14:44:52.247

Link: CVE-2026-63571

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature