CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tikato a version that resolves this vulnerability.Fixed in 4.0.0-beta-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66756?
CVE-2026-66756 has a medium severity rating of 6.9 on the CVSS scale.
How do I fix CVE-2026-66756?
To fix CVE-2026-66756, upgrade Apache Tika to version 4.0.0-beta-1 or later.
What type of vulnerability is CVE-2026-66756?
CVE-2026-66756 is an Improper Protection of Alternate Path vulnerability in Apache Tika.
Which versions of Apache Tika are affected by CVE-2026-66756?
Apache Tika versions from 4.0.0-alpha-1 up to, but not including, 4.0.0-beta-1 are affected by CVE-2026-66756.
What can happen if CVE-2026-66756 is exploited?
If exploited, CVE-2026-66756 could lead to the configuration of the unpack endpoint with unsecure features enabled, potentially exposing users to security risks.