# CVE-2026-59642

## Summary

- **CVE ID:** CVE-2026-59642
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/U:Amber)
- **CWE:** CWE-354
- **Published:** Aug 3, 2026
- **Last Modified:** Aug 3, 2026

## Description

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

## Affected Products

- Legion of the Bouncy Castle Inc. — BC-JAVA (0)
- Legion of the Bouncy Castle Inc. — BC-LTS-JAVA (2.73.0)
- Legion of the Bouncy Castle Inc. — BC-FJA (1.0.0)
- Legion of the Bouncy Castle Inc. — BC-FJA (2.0.0)
- Legion of the Bouncy Castle Inc. — BC-FJA (2.1.0)

## References

- [CNA](https://github.com/bcgit/bc-java/wiki/CVE-2026-59642)
- [CNA](https://github.com/bcgit/bc-java/commit/2117f316a5a47308f3e569695a6592b16aac0dd7)
- [CNA](https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059642)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._