Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an… (CVE-2026-66755)
A relative path traversal vulnerability exists in the ISA-Tab parser of Apache Tika versions 1.8 through 3.3.1 and 4.0.0-alpha-1. This flaw allows an attacker who can place files in a directory parsed by the application to read arbitrary files accessible to the Tika process. The attack leverages a crafted "Study Assay File Name" value in the ISA-Tab investigation file to traverse outside the intended dataset directory. Upgrading to Apache Tika version 3.3.2 or 4.0.0-beta-1 addresses this issue.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-66755) is a relative path traversal in the ISA-Tab parser component of Apache Tika. It affects versions from 1.8 through 3.3.1 and 4.0.0-alpha-1. An attacker with the ability to place files in a directory that Apache Tika subsequently parses can exploit this flaw by using a specially crafted "Study Assay File Name" in the ISA-Tab investigation file. This causes the parser to read files outside the intended dataset directory and include their contents in the extracted text output. The issue is fixed in versions 3.3.2 and 4.0.0-beta-1.
Potential Impact
An attacker able to place files in a directory parsed by Apache Tika can read arbitrary files accessible to the Tika process. This can lead to unauthorized disclosure of sensitive information through the extracted text output. There is no indication of privilege escalation or remote code execution. The vulnerability requires local file placement capability.
Mitigation Recommendations
Users should upgrade Apache Tika to version 3.3.2 or 4.0.0-beta-1, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the advisory recommending these versions.
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an… (CVE-2026-66755)
Description
A relative path traversal vulnerability exists in the ISA-Tab parser of Apache Tika versions 1.8 through 3.3.1 and 4.0.0-alpha-1. This flaw allows an attacker who can place files in a directory parsed by the application to read arbitrary files accessible to the Tika process. The attack leverages a crafted "Study Assay File Name" value in the ISA-Tab investigation file to traverse outside the intended dataset directory. Upgrading to Apache Tika version 3.3.2 or 4.0.0-beta-1 addresses this issue.
CVSS v4.0
Affected software
pkg:maven/org.apache.tika/tika-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-66755) is a relative path traversal in the ISA-Tab parser component of Apache Tika. It affects versions from 1.8 through 3.3.1 and 4.0.0-alpha-1. An attacker with the ability to place files in a directory that Apache Tika subsequently parses can exploit this flaw by using a specially crafted "Study Assay File Name" in the ISA-Tab investigation file. This causes the parser to read files outside the intended dataset directory and include their contents in the extracted text output. The issue is fixed in versions 3.3.2 and 4.0.0-beta-1.
Potential Impact
An attacker able to place files in a directory parsed by Apache Tika can read arbitrary files accessible to the Tika process. This can lead to unauthorized disclosure of sensitive information through the extracted text output. There is no indication of privilege escalation or remote code execution. The vulnerability requires local file placement capability.
Mitigation Recommendations
Users should upgrade Apache Tika to version 3.3.2 or 4.0.0-beta-1, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed by the advisory recommending these versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vrmh-37mg-28h3
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-66755"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a6bdd869c2644c7f8da6fbd
Added to database: 07/30/2026, 23:25:58 UTC
Last enriched: 07/30/2026, 23:30:45 UTC
Last updated: 07/31/2026, 02:51:54 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.