Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-0636

26
FAUCET Score

CVE-2026-0636 is an LDAP injection vulnerability in Legion of the Bouncy Castle Inc.'s BC-JAVA bcprov library affecting versions 1.74 through 1.83, with the vulnerable code residing in the LDAPStoreHelper program file. The flaw stems from improper neutralization of special elements used in LDAP queries, allowing attackers to manipulate query logic. This vulnerability carries a FAUCET Risk Score of 41.0 out of 100 with an EPSS score of 0.00062, indicating relatively low exploitation probability at present. There is no current evidence of active exploitation, no public exploit code availability, and the vulnerability remains on the inactive hot list, suggesting minimal community attention and real-world threat activity. Organizations using affected BC-JAVA versions should apply patches to version 1.84 or later, though the low risk metrics suggest this is not an immediate critical priority.

Impacted Technologies

VendorProductVersion(s)CPE
Legion Of The Bouncy Castle Inc.BC-JAVA
>= 1.74, < 1.80.2, >= 1.81, < 1.81.1, >= 1.82, < 1.84CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 26th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk14Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk15to18Fixed in: 1.84
mavenpatch availablevia ghsa
Product: org.bouncycastle:bcprov-jdk18onFixed in: 1.84

Vendor Advisories (1)

mavenGHSA-c3fc-8qff-9hwxmedium

Bouncy Castle has an LDAP injection

Apr 17, 2026

References

access.redhat.com / errata/RHSA-2026:11720
access.redhat.com / errata/RHSA-2026:11721
access.redhat.com / errata/RHSA-2026:13631
access.redhat.com / errata/RHSA-2026:14272
access.redhat.com / errata/RHSA-2026:14276
access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / errata/RHSA-2026:21772
access.redhat.com / security/cve/CVE-2026-0636
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-0636.json
github.com / bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde
github.com / bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636