CVE-2026-94114: Apache Software Foundation Apache Commons Bcel

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.

Affected products

Published 2026-10-06. Last modified 2026-10-08.