CVE-2026-71890 | Legion of the Bouncy Castle BC-JAVA up to 1.85 External Commit Proposal Validator Group.java privileges management

SecurityVulns

A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.85. It has been classified as critical. Impacted is the function org.bouncycastle.mls.protocol.Group.validateExternalCachedProposals of the file Group.java of the component External Commit Proposal Validator. This manipulation causes improper privilege management.

This vulnerability is handled as CVE-2026-71890. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More