THREATOPS
THREAT OPSThreat News › CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

CVE-2026-66756: Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false

medoss_secPublished 2026-07-30

<p>Posted by Tim Allison on Jul 30</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache Tika (org.apache.tika:tika-server) 4.0.0-alpha-1 before 4.0.0-beta-1<br /> <br /> Description:<br /> <br /> Improper Protection of Alternate Path vulnerability in Apache Tika.<br /> <br /> This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1.<br /> <br /> Users are recommended t

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/349