PT-2026-66570 · Apache+2 · Apache Tika+2
CVE-2026-66755
·
Published
2026-07-30
·
Updated
2026-09-03
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Software Foundation Apache Tika versions 1.8 through 3.3.1
Apache Software Foundation Apache Tika version 4.0.0-alpha-1
Description
A relative path traversal issue exists in the ISA-Tab parser. An attacker capable of placing files in a directory parsed by the application can read arbitrary files accessible to the Tika process. This is achieved by using a malicious value in the
Study Assay File Name variable within an ISA-Tab investigation file to traverse outside the dataset directory, causing the contents of the targeted files to be emitted into the extracted text output.Recommendations
Upgrade versions 1.8 through 3.3.1 to version 3.3.2.
Upgrade version 4.0.0-alpha-1 to version 4.0.0-beta-1.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tika
Linuxmint
Ubuntu