Intel

AIKIDO-2026-713144

bcmls-jdk18on is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-71890 Published Yesterday

85

High Risk

This Affects:

JAVAbcmls-jdk18on
1.78 - 1.85
Fixed in 1.86
Are you affected? Scan for Free

TL;DR

MLS external-commit validation lets a joiner remove an arbitrary existing member because the removed credential is not tied to the joiner. The fix requires the removed leaf credential to equal the external joiner's new-leaf credential on both the send and receive paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your MLS group accepts external commits from parties that possess the group's public GroupInfo.

Background info

bcmls-jdk18on is vulnerable to Missing Authorization in versions 1.78 - 1.85.

How to fix this

Upgrade the bcmls-jdk18on library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform