SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66756

CRITICAL · CVSS 9.8 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache Tika versions prior to 4.0.0-beta-1 are vulnerable to an improper protection of alternate path issue, which could potentially allow unauthorized access to sensitive resources. Organizations utilizing affected versions should prioritize upgrading to the latest beta release to mitigate potential security risks. This is particularly critical for those relying on Tika for content analysis and processing in their applications.

CVE
CVE-2026-66756
Severity
CRITICAL
CVSS
9.8
EPSS
0.45%
Apache

Original NVD Description

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)