CVE Field Guide
About Us
CVE-2026-59652
PUBLISHED
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
Assigner:
bcorg
Reserved:
06.07.2026
Published:
03.08.2026
Updated:
03.08.2026
In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy jdk1.4 LDAPStoreHelper.
Metrics
CVSS 4.0
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/U:Amber
CVSS Score:
6.9
CVSS score
6.9
Exploitability Metrics
Vulnerable System Impact Metrics
Subsequent System Impact Metrics
Attack Vector
Network
Confidentiality
Low
Confidentiality
None
Attack Complexity
Low
Integrity
Low
Integrity
None
Attack Requirements
None
Availability
None
Availability
None
Privileges Required
None
User Interaction
None
CVSS 4.0
Product Status
Vendor
Legion of the Bouncy Castle Inc.
Product
BC-JAVA
Versions
Default:
unaffected
affected from 0 to 1.85 (excl.)
Credits
Alex Gaynor in collaboration with Claude and Anthropic Research
reporter
References
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059652
https://github.com/bcgit/bc-java/commit/27c468af54ee6c6af87eab5a3a8468dce17e24a0
Problem Types
CWE-90 Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')
CWE