A vulnerability was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java FIPS and Bouncy Castle for Java LTS. It has been rated as critical. Affected by this issue is the function verifySignatures of the component CMS. This manipulation causes improper authentication.

This vulnerability is handled as CVE-2026-59639. The attack can be initiated remotely. There is not any exploit available.