Junglewise Threat Intelligence

CVE-2026-66756: Apache Tika path protection bypass in tika-server unpack endpoint

CVE-2026-66756 · Severity: info · CVSS 6.9 · Published 2026-07-30

Executive brief

Apache Tika, a tool used for detecting and extracting metadata and text from various file types, contains a vulnerability in its server component. The 'unpack' feature fails to properly restrict certain file paths even when security protections are supposedly enabled. This could allow an attacker to bypass security configurations, potentially leading to unauthorized file access or manipulation on the server.

Technical details

An Improper Protection of Alternate Path (CWE-424) vulnerability exists in the 'unpack' endpoint of Apache Tika-server. The flaw allows the endpoint to be configured or utilized in a way that bypasses security restrictions, specifically when 'unsecureFeatures' is set to false. This vulnerability affects versions 4.0.0-alpha-1 through 4.0.0-beta-1. An attacker could potentially exploit this to access or write to unintended file paths on the host system. The issue is resolved in version 4.0.0-beta-1.

Affected products

  • Apache Software Foundation Apache Tika 4.0.0-alpha-1 to 4.0.0-beta-1

Timeline

  • 2026-07-30: disclosed: Advisory published by Apache Software Foundation
  • 2026-07-30: patched: Fixed in version 4.0.0-beta-1

References