---
id: CVE-2026-15999
title: >-
  Improper validation of integrity check value in the AES-CCM implementation
  (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc
summary: >-
  Improper validation of integrity check value in the AES-CCM implementation
  (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc.
  bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted
  content without d…
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-354
vendor: Legion of the Bouncy Castle Inc.
product: BouncyCastle.Cryptography
affected:
  - BouncyCastle.Cryptography < 2.7.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T07:16:36.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15999'
references:
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/2818bdfa55efd58b0d6a1c75f360b8404d879780
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: >-
      https://github.com/bcgit/bc-csharp/commit/9d284d8f379614def853b590c62bbb31c48f7af0
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
  - url: 'https://github.com/bcgit/bc-csharp/wiki/CVE-2026-15999'
    label: 91579145-5d7b-4cc5-b925-a0262ff19630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-02T07:13:06.672Z'
---

## Overview

Improper validation of integrity check value in the AES-CCM implementation (CcmParameters and CcmBlockCipher) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to modify CCM-encrypted content without detection via an AlgorithmIdentifier whose CCMParameters declare an authentication tag (aes-ICVlen) of zero or another length outside the RFC 5084 set, because CcmParameters accepted any value and CcmBlockCipher validated the tag length only when encrypting, so decryption compared a zero-length or very short tag. Affected paths include ParameterUtilities.GetCipherParameters, used by CmsEnvelopedData and CmsEnvelopedDataParser for EnvelopedData encrypted with AES-CCM, and any caller passing an unchecked tag length to CcmBlockCipher for decryption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
