CVE-2026-66755
Apache Tika: Arbitrary Local File Read in ISArchiveParser
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.
| CWE | CWE-22 |
| Vendor | apache software foundation |
| Product | apache tika |
| Published | Jul 30, 2026 |
| Last Updated | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache tika
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache tika are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Tika
1.8 < 3.3.2 4.0.0-alpha-1 < 4.0.0-beta-1
References
Credits
Reported by BugQore, who supplied a patch in PR #2873. Independently reported with proposed fix by Rui Heng Koh.