Apache Tika 4.0.0-alpha-1 to 4.0.0-beta-1: Improper Alternate Path Protection
CVE-2026-66756 Published on July 30, 2026
Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Vulnerability Analysis
CVE-2026-66756 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Improper Protection of Alternate Path
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Products Associated with CVE-2026-66756
Want to know whenever a new CVE is published for Apache Tika? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tika:- Version 4.0.0-alpha-1 and below 4.0.0-beta-1 is affected.