Path traversal in Apache Tika - CVE-2026-66755

 

Path traversal in Apache Tika - CVE-2026-66755

Published: August 24, 2026


Vulnerability identifier: #VU144802
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66755
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in ISArchiveParser when parsing an ISA-Tab investigation file containing a crafted "Study Assay File Name" value. A remote attacker can place files in a directory that the application subsequently parses to disclose sensitive information.

The issue can cause contents of arbitrary files accessible to the Tika process to be emitted into the extracted text output.


Affected software

Apache Tika
Ubuntu
tika (Ubuntu package)

How to mitigate CVE-2026-66755

Install security update from vendor's website.

Apache Tika - addressed in versions 3.3.2, 4.0.0 beta-1
tika (Ubuntu package) - addressed in versions 1.22-1ubuntu0.1~esm3, 1.22-2+deb11u1ubuntu0.1~esm2

External References

Related Security Bulletins