CVE-2026-94114
Received
Received - Intake
Symbolic Link Name Misuse in Apache Commons BCEL
Vulnerability report for CVE-2026-94114, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: Apache Software Foundation
Description
Description
Symbolic name not mapping to correct object vulnerability in Apache Commons.
BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class.
This issue affects Apache Commons: before 6.13.0.
Users are recommended to upgrade to version 6.13.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Apache | Software | Foundation Apache Commons BCEL 0 |
| Apache | Software | Foundation Apache Commons BCEL 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-386 | A constant symbolic reference to an object is used, even though the reference can resolve to a different object over time. |