Path Traversal Vulnerability in Apache Tika Affects Multiple Versions
CVE-2026-66755

5.9MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 July 2026

What is CVE-2026-66755?

A path traversal vulnerability in the ISA-Tab parser of Apache Tika allows attackers to manipulate files within specified directories. By exploiting this flaw, an attacker can read arbitrary files accessible to the Tika process, potentially exposing sensitive information. The issue arises when attackers employ a crafted 'Study Assay File Name' in the ISA-Tab investigation file, enabling them to traverse outside the authorized dataset directory. Users of Tika are urged to upgrade to version 3.3.2 or 4.0.0-beta-1 to mitigate the risk associated with this vulnerability.

Affected Version(s)

Apache Tika 1.8 < 3.3.2

Apache Tika 4.0.0-alpha-1 < 4.0.0-beta-1

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Reported by BugQore, who supplied a patch in PR #2873.
Independently reported with proposed fix by Rui Heng Koh.
.