A vulnerability labeled as problematic has been found in Legion of the Bouncy Castle Bouncy Castle for Java and Bouncy Castle for Java LTS. This affects an unknown part of the component KCCMBlockCipher MAC. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2026-12803. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.