Description
Improper Protection of Alternate Path vulnerability in Apache Tika.

This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.

Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Published: 2026-07-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an Improper Protection of Alternate Path (CWE‑424). Attackers can manipulate the unpack endpoint when the unsecureFeatures setting is not secured, enabling reference to arbitrary file paths and reading of sensitive files. This leads to information disclosure. No evidence of remote code execution is documented.

Affected Systems

Apache Tika Server versions from 4.0.0‑alpha‑1 up to, but not including, 4.0.0‑beta‑1 are vulnerable. Earlier releases are not affected.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. An EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote use of the network‑facing unpack endpoint, particularly when the unsecureFeatures configuration is set to an insecure value. No evidence of exploitation has been observed. Upgrading to 4.0.0‑beta‑1 removes the issue.

Generated by OpenCVE AI on August 3, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Apache Tika to version 4.0.0‑beta‑1 or later.
  • If an immediate update is not possible, restrict the unpack endpoint to trusted hosts or internal networks only.
  • Disable the unpack endpoint or remove the unsecureFeatures configuration when it is not required.

Generated by OpenCVE AI on August 3, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tika
Vendors & Products Apache
Apache tika

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Title Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Weaknesses CWE-424
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-30T19:33:01.657Z

Reserved: 2026-07-27T17:13:07.869Z

Link: CVE-2026-66756

cve-icon Vulnrichment

Updated: 2026-07-30T19:30:52.794Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T20:18:13.877

Modified: 2026-08-10T14:15:32.937

Link: CVE-2026-66756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-424

    Improper Protection of Alternate Path