Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tika
Vendors & Products Apache
Apache tika

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Title Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Weaknesses CWE-424
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-30T19:33:01.657Z

Reserved: 2026-07-27T17:13:07.869Z

Link: CVE-2026-66756

cve-icon Vulnrichment

Updated: 2026-07-30T19:30:52.794Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T21:00:20Z