CVE-2026-94114: Apache Software Foundation Apache Commons Bcel
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
Symbolic name not mapping to correct class. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons BCEL: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Affected products
- Apache Software Foundation Apache Commons Bcel: before 6.13.0 (fixed in 6.13.0)
Published 2026-10-06. Last modified 2026-10-08.