CVE-2026-59642: CMS AuthenticatedData content not bound to MAC when authAttrs present
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59642?
CVE-2026-59642 has a risk score of 51, indicating a moderate level of severity.
How do I fix CVE-2026-59642?
To mitigate CVE-2026-59642, upgrade to Bouncy Castle for Java version 1.85 or later, or the appropriate LTS or FIPS version.
What is the impact of CVE-2026-59642 on CMS AuthenticatedData?
CVE-2026-59642 allows the content of CMS AuthenticatedData to be not bound to MAC when authAttrs are present, which may lead to integrity issues.
Which versions of Bouncy Castle are affected by CVE-2026-59642?
CVE-2026-59642 affects Bouncy Castle for Java versions prior to 1.85, as well as the LTS and FIPS versions before specified updates.
What should I do if I cannot upgrade from the affected versions due to compatibility issues?
If upgrading is not possible, consider implementing additional security controls to monitor and validate data integrity.