Vulnerability in Bouncy Castle Java: External Commit Proposal Manipulation
CVE-2026-71890
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-71890?
A vulnerability in Bouncy Castle for Java versions prior to 1.86 allows an external joiner to manipulate external commit proposals, potentially leading to unauthorized evictions from a ratchet tree. The flaw exists due to inadequate validation of removal proposals in the MLS (RFC 9420) external commit process. Specifically, it fails to verify that a removed leaf pertains to the joiner, allowing any entity with access to the public GroupInfo to remove and replace valid members. This oversight is significant because it enables an attacker to take over another member’s slot within the group structure without adequate checks, jeopardizing the integrity and security of group communications.
Affected Version(s)
BC-JAVA all 1.73 < 1.86
