Symbolic Name Mapping Vulnerability in Apache Commons
CVE-2026-94114

8.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
6 October 2026

What is CVE-2026-94114?

A vulnerability in Apache Commons BCEL allows attacker-controlled classes to be cached under self-declared names without proper validation. This can lead to issues where lookups and verification results mistakenly refer to different, potentially malicious classes, compromising system integrity. Users are urged to upgrade to version 6.13.0 to mitigate this risk.

Affected Version(s)

Apache Commons BCEL 0 < 6.13.0

Apache Commons BCEL 0 < 14890bf2b9014df25f9b4de86f29b5e917e5656b

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Apache Software Foundation
Claude Security
.