Intel

AIKIDO-2026-417589

bcpg-jdk18on is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-71886 Published Yesterday

55

Medium Risk

This Affects:

JAVAbcpg-jdk18on
1.81 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

The high-level OpenPGP API accepts third-party certifications and trust delegations from subkeys that were never granted certification authority, so a restricted subkey can be treated as an introducer. The fix requires a non-primary issuer component to hold CERTIFY_OTHER.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the high-level OpenPGP certificate API to make identity or introducer-trust decisions from certifications or delegations.

Background info

bcpg-jdk18on is vulnerable to Incorrect Authorization in versions 1.81 - 1.85.

How to fix this

Upgrade the bcpg-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform