PT-2026-66570 · Apache+2 · Apache Tika+2

CVE-2026-66755

·

Published

2026-07-30

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Software Foundation Apache Tika versions 1.8 through 3.3.1 Apache Software Foundation Apache Tika version 4.0.0-alpha-1
Description A relative path traversal issue exists in the ISA-Tab parser. An attacker capable of placing files in a directory parsed by the application can read arbitrary files accessible to the Tika process. This is achieved by using a malicious value in the Study Assay File Name variable within an ISA-Tab investigation file to traverse outside the dataset directory, causing the contents of the targeted files to be emitted into the extracted text output.
Recommendations Upgrade versions 1.8 through 3.3.1 to version 3.3.2. Upgrade version 4.0.0-alpha-1 to version 4.0.0-beta-1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66755
USN-8717-1

Affected Products

Apache Tika
Linuxmint
Ubuntu