CVE-2026-94114
HIGH
8,2
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none
Description
AI Translation Available
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
386
Symbolic Name not Mapping to Correct Object
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Other
Non-Repudiation
Potential Impacts:
Gain Privileges Or Assume Identity
Modify Application Data
Modify Files Or Directories
Read Application Data
Read Files Or Directories
Other
Hide Activities
Applicable Platforms
All platforms may be affected
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e91…
https://lists.apache.org/thread.html/d87nxx7nb5bombqggxhxo9lz16nwtsf9