CVE-2026-59639

HIGH

CMS verifySignatures returns true for SignedData with zero signers

Title source: cna
STIX 2.1

Description

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

Scores

CVSS v4 8.7
EPSS 0.0017
EPSS Percentile 7.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (5)
Legion of the Bouncy Castle Inc./BC-FJA 1.0.0 - 1.0.12
Legion of the Bouncy Castle Inc./BC-FJA 2.0.0 - 2.0.12
Legion of the Bouncy Castle Inc./BC-FJA 2.1.0 - 2.1.12
Legion of the Bouncy Castle Inc./BC-JAVA < 1.85
Legion of the Bouncy Castle Inc./BC-LTS-JAVA 2.73.0 - 2.73.12
Published Aug 03, 2026
Tracked Since Aug 03, 2026