CVE-2026-0636 is an LDAP injection vulnerability in Legion of the Bouncy Castle Inc.'s BC-JAVA bcprov library affecting versions 1.74 through 1.83, with the vulnerable code residing in the LDAPStoreHelper program file. The flaw stems from improper neutralization of special elements used in LDAP queries, allowing attackers to manipulate query logic. This vulnerability carries a FAUCET Risk Score of 41.0 out of 100 with an EPSS score of 0.00062, indicating relatively low exploitation probability at present. There is no current evidence of active exploitation, no public exploit code availability, and the vulnerability remains on the inactive hot list, suggesting minimal community attention and real-world threat activity. Organizations using affected BC-JAVA versions should apply patches to version 1.84 or later, though the low risk metrics suggest this is not an immediate critical priority.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Legion Of The Bouncy Castle Inc. | BC-JAVA | >= 1.74, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.