Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-94114

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Oct 06, 2026
Vendor unknown

Description

Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.

References