๐Ÿ” CVE Alert

CVE-2026-66755

UNKNOWN 0.0

Apache Tika: Arbitrary Local File Read in ISArchiveParser

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.

CWE CWE-22
Vendor apache software foundation
Product apache tika
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache tika

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache tika are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Tika
1.8 < 3.3.2 4.0.0-alpha-1 < 4.0.0-beta-1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/0hcctcp9s5lxgq2ookp4o6chltk99f8r openwall.com: http://www.openwall.com/lists/oss-security/2026/07/30/23

Credits

Reported by BugQore, who supplied a patch in PR #2873. Independently reported with proposed fix by Rui Heng Koh.