Allow-List Bypass Vulnerability in Apache MINA Product by Apache
CVE-2026-94301

9.8CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94301?

A significant vulnerability exists in Apache MINA where versions 2.0.29 and 2.1.13, and subsequent releases, do not implement the necessary override for resolveProxyClass(), leading to a potential allow-list bypass. This oversight occurs despite fixes being committed to the 2.2.X branch, leaving earlier maintenance branches susceptible to exploitation. The failure to address this issue effectively in the older branches exposes users to risks associated with unauthorized access and manipulation.

Affected Version(s)

Apache MINA 2.0.0 < 2.0.31

Apache MINA 2.1.0 < 2.1.15

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tonghuaroot
.