Apache Tika 4.0.0-alpha-1 to 4.0.0-beta-1: Improper Alternate Path Protection
CVE-2026-66756 Published on July 30, 2026

Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-66756 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Improper Protection of Alternate Path

The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.


Products Associated with CVE-2026-66756

Want to know whenever a new CVE is published for Apache Tika? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Tika: