OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-15999

HIGH · CVSS 8.2 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability arises from improper validation of the integrity check value in the AES-CCM implementation, allowing an on-path attacker to modify encrypted content undetected. This flaw affects any application utilizing the Legion of the Bouncy Castle library prior to version 2.7.0 that processes AES-CCM encrypted data, particularly through the CmsEnvelopedData and CmsEnvelopedDataParser components. Organizations using this library for secure communications should prioritize patching to mitigate the risk of unauthorized data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15999
Severity
HIGH
CVSS
8.2
EPSS
0.23%

Original NVD Description

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption.