PatchSiren cyber security CVE debrief
CVE-2026-71886 Legion of the Bouncy Castle Inc. CVE debrief
A vulnerability in Bouncy Castle for Java before version 1.86 allows for incorrect attribution of third-party certifications or trust delegations, potentially leading to identity or trusted-introducer decisions being attributed to an offline primary key. This could allow a subkey bound only with SIGN_DATA to issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust. The vulnerability is related to the high-level OpenPGP certificate API in Bouncy Castle for Java, which incorrectly accepted third-party certifications or trust delegations without proper verification of the issuing component's CERT
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for systems using Bouncy Castle for Java, especially those using OpenPGP certificate APIs, should assess the potential impact and verify the affected library versions.
Why it matters
The vulnerability in Bouncy Castle for Java could lead to incorrect security decisions, potentially allowing compromised subkeys to be promoted to primary key authority, and requires verification and monitoring.
- Potential incorrect attribution of third-party certifications or trust delegations
- Possible security consequences due to incorrect identity or trusted-introducer decisions
- Verification priority for Bouncy Castle library versions and OpenPGP certificate API usage
- Need for monitoring and incident response planning
Technical summary
The Bouncy Castle for Java library before version 1.86 contains a vulnerability in its high-level OpenPGP certificate API. The API incorrectly accepts third-party certifications or trust delegations from any component key of the issuing certificate, without requiring that component to have been granted the authority to certify. This could allow a subkey bound only with SIGN_DATA to issue a positive User ID certification over an attacker-controlled identity, or a full-trust depth-one direct-key delegation of introducer trust.
Defensive priority
Defenders should prioritize verifying the affected Bouncy Castle library versions and assessing the potential impact on their systems, especially those using OpenPGP certificate APIs.
Recommended defensive actions
- Verify Bouncy Castle library versions and assess potential impact
- Review and update OpenPGP certificate API usage
- Monitor for potential security consequences
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is related to the high-level OpenPGP certificate API in Bouncy Castle for Java, which incorrectly accepted third-party certifications or trust delegations without proper verification of the issuing component's authority.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71886 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71886
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71886 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71886
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/f0d5c8535aeff3f34b7b6b6289ee78c2ea36a3fb
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071886
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.