Description
In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2 makes the MAC cover the DER encoding of authAttrs when they are present and the eContent OCTET STRING directly when they are not. CMSAuthenticatedDataParser has to choose between those two in its constructor, before it can reach authAttrs, which comes later in the SEQUENCE, so it chose on digestAlgorithm alone: for a message with digestAlgorithm absent but authAttrs present it verified the content MAC and then returned the attributes through getAuthAttrs() as though they had been authenticated, when the MAC had never covered them. An attacker able to modify a message in transit could insert an authenticated attribute, such as an RFC 2634 ESSSecurityLabel, into an otherwise valid message while holding neither the key-encryption key nor the content-MAC key, and an application taking an authorization, routing or labelling decision from those attributes would act on attacker-chosen values. The content itself remained MAC-bound. asn1.cms.AuthenticatedData now rejects the mismatched pairing when parsing and CMSAuthenticatedDataParser cross-checks the two fields once authAttrs is read. This is a variant of CVE-2026-59642, which bound the content to the MAC for messages that legitimately carry authAttrs, and which does not address this case. This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), and bcutil-fips 2.0.8 (2.0.X series) and 2.1.8 (2.1.X series).
Published: 2026-10-03
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized attribute manipulation
Action: Apply Patch
AI Analysis

Impact

In Bouncy Castle for Java versions prior to 1.86, the CMS AuthenticatedData parser incorrectly handled messages where the digestAlgorithm field was missing but authenticated attributes were present. The library treated the attributes as authenticated even though the MAC did not cover them, enabling an attacker to inject attributes such as ESSSecurityLabel without possessing any cryptographic keys. Consequently, applications that rely on these attributes for authorization, routing or labelling would act on attacker‑controlled values while the message content itself remained integrity‑protected.

Affected Systems

Legion of the Bouncy Castle Inc. products—including BC-JAVA, BC-FJA, and BC-LTS-JAVA—are affected. The vulnerability applies to Bouncy Castle Java releases before 1.86, to the LTS branch before 2.73.13, and to Bouncy Castle for Java FIPS prior to bcpkix‑fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), as well as to bcutil‑fips before versions 2.0.8 and 2.1.8.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, and although EPSS data is unavailable, the flaw can be exploited by intercepting or modifying legitimate CMS AuthenticatedData streams without requiring any secret keys. The vulnerability is not currently listed in the CISA KEV catalog, but its impact on authorization logic makes it a significant threat; attackers can subvert security decisions while keeping the message content intact.

Generated by OpenCVE AI on October 3, 2026 at 09:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Bouncy Castle Java release (≥ 1 86) or the LTS release (≥ 2 73.13) to replace vulnerable libraries.
  • Upgrade Bouncy Castle for Java FIPS to at least bcpkix‑fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series), or 2.1.13 (2.1.X series) and bcutil‑fips to ≥ 2.0.8 or ≥ 2.1.8.
  • If an immediate update is not feasible, disable or bypass the use of CMS AuthenticatedData parsers that accept messages with mismatched digestAlgorithm and authAttrs, or implement manual verification that MAC covers any disclosed attributes before using them for authorization decisions.

Generated by OpenCVE AI on October 3, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java
Vendors & Products Legion Of The Bouncy Castle Inc.
Legion Of The Bouncy Castle Inc. bc-fja
Legion Of The Bouncy Castle Inc. bc-java
Legion Of The Bouncy Castle Inc. bc-lts-java

Sat, 03 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description In Bouncy Castle for Java before 1.86, the streaming CMS AuthenticatedData parser accepted a message whose digestAlgorithm and authAttrs fields disagreed about whether authenticated attributes were present. RFC 5652 sec. 9.1 pairs the two, requiring that authAttrs be present whenever digestAlgorithm is, and sec. 9.2 makes the MAC cover the DER encoding of authAttrs when they are present and the eContent OCTET STRING directly when they are not. CMSAuthenticatedDataParser has to choose between those two in its constructor, before it can reach authAttrs, which comes later in the SEQUENCE, so it chose on digestAlgorithm alone: for a message with digestAlgorithm absent but authAttrs present it verified the content MAC and then returned the attributes through getAuthAttrs() as though they had been authenticated, when the MAC had never covered them. An attacker able to modify a message in transit could insert an authenticated attribute, such as an RFC 2634 ESSSecurityLabel, into an otherwise valid message while holding neither the key-encryption key nor the content-MAC key, and an application taking an authorization, routing or labelling decision from those attributes would act on attacker-chosen values. The content itself remained MAC-bound. asn1.cms.AuthenticatedData now rejects the mismatched pairing when parsing and CMSAuthenticatedDataParser cross-checks the two fields once authAttrs is read. This is a variant of CVE-2026-59642, which bound the content to the MAC for messages that legitimately carry authAttrs, and which does not address this case. This issue also affects Bouncy Castle for Java LTS before 2.73.13, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), and bcutil-fips 2.0.8 (2.0.X series) and 2.1.8 (2.1.X series).
Title CMS AuthenticatedData exposes attacker-inserted authAttrs when digestAlgorithm is absent
Weaknesses CWE-354
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Legion Of The Bouncy Castle Inc. Bc-fja Bc-java Bc-lts-java
cve-icon MITRE

Status: PUBLISHED

Assigner: bcorg

Published:

Updated: 2026-10-03T08:36:12.960Z

Reserved: 2026-08-08T00:06:07.401Z

Link: CVE-2026-71888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-03T09:17:05.250

Modified: 2026-10-03T09:17:05.250

Link: CVE-2026-71888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T10:00:12Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value