Impact
The vulnerability resides in Bouncy Castle for Java prior to version 1.86, where validation of an MLS external commit's proposal list fails to check that the removed leaf matches the joiner's own new leaf. This allows any party holding the group's public GroupInfo, the data an external joiner receives, to craft a commit that removes any member's LeafIndex. The affected members will apply this commit, evicting the targeted member and allowing the attacker to take over the slot. As a result, the attacker can gain unauthorized participation in the group, undermining confidentiality and integrity.
Affected Systems
Legion of the Bouncy Castle Inc.'s Bouncy Castle for Java (BC-JAVA) library, any installation using a version earlier than 1.86.
Risk and Exploitability
The CVSS base score of 8.7 classifies this flaw as high severity. No EPSS score is publicly available, but the flaw can be exploited by any entity that can supply a crafted external commit, which is essentially an authenticated or unauthenticated network call to Group.externalJoin or Group.handle. The lack of credential validation in these APIs eliminates a critical guard, meaning the attack can be executed without privileged credentials. Because the vulnerability is not listed in KEV, it is not known to be actively exploited in the wild yet, but it presents a significant risk for any deployment relying on the exposed APIs.
OpenCVE Enrichment