CVE-2026-94114

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,2
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,9
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: high
Availability: none

Description

AI Translation Available

Symbolic name not mapping to correct object vulnerability in Apache Commons.

BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.

This issue affects Apache Commons: before 6.13.0.

Users are recommended to upgrade to version 6.13.0, which fixes the issue.

386

Symbolic Name not Mapping to Correct Object

Draft
Common Consequences
Security Scopes Affected:
Access Control Integrity Confidentiality Other Non-Repudiation
Potential Impacts:
Gain Privileges Or Assume Identity Modify Application Data Modify Files Or Directories Read Application Data Read Files Or Directories Other Hide Activities
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e91…
https://lists.apache.org/thread.html/d87nxx7nb5bombqggxhxo9lz16nwtsf9