Impact
In Bouncy Castle for Java versions prior to 1.86, the CMS AuthenticatedData parser incorrectly handled messages where the digestAlgorithm field was missing but authenticated attributes were present. The library treated the attributes as authenticated even though the MAC did not cover them, enabling an attacker to inject attributes such as ESSSecurityLabel without possessing any cryptographic keys. Consequently, applications that rely on these attributes for authorization, routing or labelling would act on attacker‑controlled values while the message content itself remained integrity‑protected.
Affected Systems
Legion of the Bouncy Castle Inc. products—including BC-JAVA, BC-FJA, and BC-LTS-JAVA—are affected. The vulnerability applies to Bouncy Castle Java releases before 1.86, to the LTS branch before 2.73.13, and to Bouncy Castle for Java FIPS prior to bcpkix‑fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series), as well as to bcutil‑fips before versions 2.0.8 and 2.1.8.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and although EPSS data is unavailable, the flaw can be exploited by intercepting or modifying legitimate CMS AuthenticatedData streams without requiring any secret keys. The vulnerability is not currently listed in the CISA KEV catalog, but its impact on authorization logic makes it a significant threat; attackers can subvert security decisions while keeping the message content intact.
OpenCVE Enrichment