CVE-2026-71888 | Legion of the Bouncy Castle BC-JAVA/BC-LTS-JAVA/BC-FJA up to 2.73.12 Streaming CMS AuthenticatedData Parser AuthenticatedData.java CMSAuthenticatedDataParser digestAlgorithm/authAttrs improper authorization
A vulnerability, which was classified as critical, was found in Legion of the Bouncy Castle BC-JAVA, BC-LTS-JAVA and BC-FJA up to 2.73.12. This affects the function CMSAuthenticatedDataParser of the file asn1/cms/AuthenticatedData.java of the component Streaming CMS AuthenticatedData Parser. Executing a manipulation of the argument digestAlgorithm/authAttrs can lead to improper authorization.
This vulnerability appears as CVE-2026-71888. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More