Vulnerability Details CVE-2026-66756
Improper Protection of Alternate Path vulnerability in Apache Tika.
This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.
Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 23.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-66756
-
cpe:2.3:a:apache:tika:4.0.0