CVE-2026-94114
MEDIUMDescription
Symbolic name not mapping to correct object vulnerability in Apache Commons. BCEL caches attacker-controlled classes under their self-declared names without validating the requested name, allowing subsequent lookups and name-keyed verification results to refer to a different class. This issue affects Apache Commons: before 6.13.0. Users are recommended to upgrade to version 6.13.0, which fixes the issue.
Is your site exposed to CVE-2026-94114?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-94114? +
How severe is CVE-2026-94114? +
How do I check if I'm vulnerable to CVE-2026-94114? +
Related Vulnerabilities
In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars When …
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, …