CVE-2026-66756
published 2026-07-30CVE-2026-66756: Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
37.2th percentile
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| apache | tika | — | — |
| apache_software_foundation | apache_tika | >= 4.0.0-alpha-1 < 4.0.0-beta-1 | 4.0.0-beta-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Protection of Alternate Path vulnerability in Apache Tika.
ghsa_unreviewed·2026-07-30
CVE-2026-66756 [MEDIUM] CWE-424 Improper Protection of Alternate Path vulnerability in Apache Tika.
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
VulDB
Apache Tika up to 4.0.0-beta-0 path traversal (EUVD-2026-51279)
vuldb·2026-07-30·CVSS 6.9
CVE-2026-66756 [MEDIUM] Apache Tika up to 4.0.0-beta-0 path traversal (EUVD-2026-51279)
A vulnerability marked as critical has been reported in Apache Tika up to 4.0.0-beta-0. Affected by this issue is some unknown functionality. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-66756. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-30
Published