PatchSiren cyber security CVE debrief
CVE-2026-71890 Legion of the Bouncy Castle Inc. CVE debrief
CVE-2026-71890 is a vulnerability in Bouncy Castle for Java before version 1.86, which allows an external joiner to evict any member from a group by sending a malicious Remove proposal in an external commit. This is possible because the validation of the proposal list did not properly check the credential of the removed leaf. As a result, an attacker holding the group's public GroupInfo can commit a Remove proposal naming any member's LeafIndex, causing that member to be evicted and allowing the attacker to take over their slot in the ratchet tree.
- Vendor
- Legion of the Bouncy Castle Inc.
- Product
- BC-JAVA
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for Bouncy Castle for Java implementations should assess exposure and prioritize verification and patching to prevent potential exploitation. This includes reviewing the system's exposure to the vulnerability, verifying the version of Bouncy Castle for Java in use, and applying the patch. Additionally, defenders should ensure that the group's public GroupInfo is properly secured and monitor for any suspicious activity related to the B
Why it matters
CVE-2026-71890 is a vulnerability in Bouncy Castle for Java that allows an external joiner to evict any member from a group, potentially allowing an attacker to take over their slot in the ratchet tree. Defenders responsible for Bouncy Castle for Java implementations should assess exposure and prioritize verification and patching to prevent potential exploitation.
- An external joiner can evict any member from a group, potentially allowing an attacker to take over their slot in the ratchet tree.
- The vulnerability can be exploited by an attacker holding the group's public GroupInfo.
- Verification of the Bouncy Castle for Java version and patching are necessary to prevent exploitation.
- Additional monitoring and review of the group's public GroupInfo may be necessary to detect potential suspicious activity.
Technical summary
The vulnerability is caused by a flawed validation of an MLS (RFC 9420) external commit's proposal list in Bouncy Castle for Java before version 1.86. This allows an external joiner to evict any member from a group by sending a malicious Remove proposal in an external commit. The validation did not properly check the credential of the removed leaf, enabling an attacker holding the group's public GroupInfo to commit a Remove proposal naming any member's LeafIndex, causing that member to be evicted and allowing the attacker to take over their slot in the ratchet tree. Defenders should prioritize verifying the version of Bouncy Castle for Java in use and applying the patch to prevent potential exploitation.
Defensive priority
Defenders should prioritize verifying the version of Bouncy Castle for Java in use and applying the patch to prevent potential exploitation.
Recommended defensive actions
- Verify the version of Bouncy Castle for Java in use and apply the patch to prevent potential exploitation.
- Review the group's public GroupInfo and ensure that it is properly secured.
- Monitor for any suspicious activity related to the Bouncy Castle for Java implementation.
- Perform a thorough review of the system's exposure to the vulnerability.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability was discovered in Bouncy Castle for Java before version 1.86. The CVE record and NVD entry provide details on the vulnerability, but no additional information on exploitation or impact is available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71890 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71890
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71890 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71890
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/commit/7e8bb10eb90baddf3f10b8679f627462b9522d24
91579145-5d7b-4cc5-b925-a0262ff19630
-
Source reference
Unverified legacy reference
URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071890
91579145-5d7b-4cc5-b925-a0262ff19630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.