Incorrect Authorization Affecting org.bouncycastle:bcpg-jdk18on package, versions [1.81,1.86)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGBOUNCYCASTLE-20419497
  • published4 Oct 2026
  • disclosed3 Oct 2026
  • creditBhargava Shastry

Introduced: 3 Oct 2026

NewCVE-2026-71886  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade org.bouncycastle:bcpg-jdk18on to version 1.86 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in OpenPGPCertificate.getCertificationBy() and getDelegationBy() in the OpenPGP certificate API. An attacker can have a third-party certification or direct-key trust delegation accepted as if it were issued by the certificate by using a component key that signed the request but was never granted CERTIFY_OTHER, such as an online signing subkey or legacy signing-capable subkey. The API resolves the signature against every component key in the issuer certificate, verifies the binding chain and signature, and then attributes the result to the certificate without checking that the signing component had certification authority when the signature was created. Applications that treat these returned chains as proof of identity binding or trusted introducer status can be tricked into trusting an attacker-controlled assertion under the offline primary key’s authority.

CVSS Base Scores

version 4.0
version 3.1