PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-71890 Legion of the Bouncy Castle Inc. CVE debrief

CVE-2026-71890 is a vulnerability in Bouncy Castle for Java before version 1.86, which allows an external joiner to evict any member from a group by sending a malicious Remove proposal in an external commit. This is possible because the validation of the proposal list did not properly check the credential of the removed leaf. As a result, an attacker holding the group's public GroupInfo can commit a Remove proposal naming any member's LeafIndex, causing that member to be evicted and allowing the attacker to take over their slot in the ratchet tree.

Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for Bouncy Castle for Java implementations should assess exposure and prioritize verification and patching to prevent potential exploitation. This includes reviewing the system's exposure to the vulnerability, verifying the version of Bouncy Castle for Java in use, and applying the patch. Additionally, defenders should ensure that the group's public GroupInfo is properly secured and monitor for any suspicious activity related to the B

Why it matters

CVE-2026-71890 is a vulnerability in Bouncy Castle for Java that allows an external joiner to evict any member from a group, potentially allowing an attacker to take over their slot in the ratchet tree. Defenders responsible for Bouncy Castle for Java implementations should assess exposure and prioritize verification and patching to prevent potential exploitation.

  • An external joiner can evict any member from a group, potentially allowing an attacker to take over their slot in the ratchet tree.
  • The vulnerability can be exploited by an attacker holding the group's public GroupInfo.
  • Verification of the Bouncy Castle for Java version and patching are necessary to prevent exploitation.
  • Additional monitoring and review of the group's public GroupInfo may be necessary to detect potential suspicious activity.

Technical summary

The vulnerability is caused by a flawed validation of an MLS (RFC 9420) external commit's proposal list in Bouncy Castle for Java before version 1.86. This allows an external joiner to evict any member from a group by sending a malicious Remove proposal in an external commit. The validation did not properly check the credential of the removed leaf, enabling an attacker holding the group's public GroupInfo to commit a Remove proposal naming any member's LeafIndex, causing that member to be evicted and allowing the attacker to take over their slot in the ratchet tree. Defenders should prioritize verifying the version of Bouncy Castle for Java in use and applying the patch to prevent potential exploitation.

Defensive priority

Defenders should prioritize verifying the version of Bouncy Castle for Java in use and applying the patch to prevent potential exploitation.

Recommended defensive actions

  • Verify the version of Bouncy Castle for Java in use and apply the patch to prevent potential exploitation.
  • Review the group's public GroupInfo and ensure that it is properly secured.
  • Monitor for any suspicious activity related to the Bouncy Castle for Java implementation.
  • Perform a thorough review of the system's exposure to the vulnerability.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability was discovered in Bouncy Castle for Java before version 1.86. The CVE record and NVD entry provide details on the vulnerability, but no additional information on exploitation or impact is available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-71890 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-71890

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-71890 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71890

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/commit/7e8bb10eb90baddf3f10b8679f627462b9522d24

    91579145-5d7b-4cc5-b925-a0262ff19630

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071890

    91579145-5d7b-4cc5-b925-a0262ff19630

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.