CVE-2026-12802
Last modified
CVE-2026-12802 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bouncycastle | Bc-Java | < 1.85 |
| Bouncycastle | Bcpkix-Fips | < 1.0.12 |
| Bouncycastle | Bcpkix-Fips | >= 2.0.7, < 2.0.12 |
| Bouncycastle | Bcpkix-Fips | >= 2.1.8, < 2.1.12 |
| Bouncycastle | Bouncy Castle For Java Lts | <= 2.73.11 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-12802?
How severe is CVE-2026-12802?
How do I fix CVE-2026-12802?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12797A security flaw has been discovered in BerriAI litellm up to…6.3
- CVE-2026-12798A weakness has been identified in BerriAI litellm up to 1.82…6.3
- CVE-2026-12799A security vulnerability has been detected in BerriAI litell…4.3
- CVE-2026-1280The Frontend File Manager Plugin for WordPress is vulnerable…7.5
- CVE-2026-12800The Premium Packages – Sell Digital Products Securely plugin…7.5
- CVE-2026-12801The Ultra Addons for Contact Form 7 plugin for WordPress is …6.4
- CVE-2026-12803In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC d…7.5
- CVE-2026-12804A vulnerability was detected in lemonldap-ng up to 2.23.0. I…4.3
- CVE-2026-12805A flaw has been found in OFFIS DCMTK up to 3.7.0. The affect…6.3
- CVE-2026-12806A vulnerability has been found in Edimax BR-6478AC V2 1.23. …8.8
- CVE-2026-12807A vulnerability was found in Edimax BR-6478AC V2 1.23. This …6.3
- CVE-2026-12808A vulnerability was determined in Edimax BR-6478AC V2 1.23. …6.3
Are you affected by CVE-2026-12802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
