PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71886 Legion of the Bouncy Castle Inc. CVE debrief

A vulnerability in Bouncy Castle for Java before version 1.86 allows for incorrect attribution of third-party certifications or trust delegations, potentially leading to identity or trusted-introducer decisions being attributed to an offline primary key. This could allow a subkey bound only with SIGN_DATA to issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust. The vulnerability is related to the high-level OpenPGP certificate API in Bouncy Castle for Java, which incorrectly accepted third-party certifications or trust delegations without proper verification of the issuing component's CERT

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for systems using Bouncy Castle for Java, especially those using OpenPGP certificate APIs, should assess the potential impact and verify the affected library versions.

Why it matters

The vulnerability in Bouncy Castle for Java could lead to incorrect security decisions, potentially allowing compromised subkeys to be promoted to primary key authority, and requires verification and monitoring.

  • Potential incorrect attribution of third-party certifications or trust delegations
  • Possible security consequences due to incorrect identity or trusted-introducer decisions
  • Verification priority for Bouncy Castle library versions and OpenPGP certificate API usage
  • Need for monitoring and incident response planning

Technical summary

The Bouncy Castle for Java library before version 1.86 contains a vulnerability in its high-level OpenPGP certificate API. The API incorrectly accepts third-party certifications or trust delegations from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. This could allow a subkey bound only with SIGN_DATA to issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust.

Defensive priority

Defenders should prioritize verifying the affected Bouncy Castle library versions and assessing the potential impact on their systems, especially those using OpenPGP certificate APIs.

Recommended defensive actions

  • Verify Bouncy Castle library versions and assess potential impact
  • Review and update OpenPGP certificate API usage
  • Monitor for potential security consequences
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is related to the high-level OpenPGP certificate API in Bouncy Castle for Java, which incorrectly accepted third-party certifications or trust delegations without proper verification of the issuing component's authority.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71886 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71886

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71886 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71886

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/f0d5c8535aeff3f34b7b6b6289ee78c2ea36a3fb

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071886

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.