CVE-2026-59642
HIGH
8,7
Source: 91579145-5d7b-4cc5-b925-a0262ff19630
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
354
Improper Validation of Integrity Check Value
DraftCommon Consequences
Security Scopes Affected:
Integrity
Other
Non-Repudiation
Potential Impacts:
Modify Application Data
Other
Hide Activities
Applicable Platforms
All platforms may be affected
https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642