SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66755

HIGH · CVSS 7.5 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Apache Tika ISA-Tab parser is vulnerable to a relative path traversal exploit, allowing attackers to read arbitrary files accessible to the Tika process by manipulating the "Study Assay File Name" parameter. This could lead to unauthorized disclosure of sensitive information contained in those files. Organizations using affected versions (1.8 through 3.3.1 and 4.0.0-alpha-1) should prioritize upgrading to version 3.3.2 or 4.0.0-beta-1 to mitigate this risk.

CVE
CVE-2026-66755
Severity
HIGH
CVSS
7.5
EPSS
0.44%
Apache

Original NVD Description

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output, via a "Study Assay File Name" value in the ISA-Tab investigation file that traverses outside the dataset directory. Users are recommended to upgrade to version 3.3.2 or 4.0.0-beta-1, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)