Path Traversal Vulnerability in Apache Tika Affects Multiple Versions
CVE-2026-66755
5.9MEDIUM
What is CVE-2026-66755?
A path traversal vulnerability in the ISA-Tab parser of Apache Tika allows attackers to manipulate files within specified directories. By exploiting this flaw, an attacker can read arbitrary files accessible to the Tika process, potentially exposing sensitive information. The issue arises when attackers employ a crafted 'Study Assay File Name' in the ISA-Tab investigation file, enabling them to traverse outside the authorized dataset directory. Users of Tika are urged to upgrade to version 3.3.2 or 4.0.0-beta-1 to mitigate the risk associated with this vulnerability.
Affected Version(s)
Apache Tika 1.8 < 3.3.2
Apache Tika 4.0.0-alpha-1 < 4.0.0-beta-1
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Reported by BugQore, who supplied a patch in PR #2873.
Independently reported with proposed fix by Rui Heng Koh.