Improper Protection of Alternate Path in Apache Tika by Apache
CVE-2026-66756
6.9MEDIUM
What is CVE-2026-66756?
An improper protection of alternate path vulnerability has been identified in Apache Tika, impacting versions prior to 4.0.0-beta-1. This issue allows unauthorized access to certain features, potentially leading to data exposure. Users are strongly advised to upgrade to version 4.0.0-beta-1 to mitigate this risk and secure their deployments effectively.
Affected Version(s)
Apache Tika 4.0.0-alpha-1 < 4.0.0-beta-1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
George Chen discovered this issue and proposed fixes