Apache disclosed CVE-2026-66756, an Improper Protection of Alternate Path vulnerability in the tika-server component of Apache Tika. The flaw affects org.apache.tika:tika-server versions from 4.0.0-alpha-1 up to, but not including, 4.0.0-beta-1, and involves the unpack endpoint permitting configuration in a way that bypasses the intended unsecureFeatures=false protection.
The project said the issue is fixed in Apache Tika 4.0.0-beta-1 and urged users running affected pre-release versions to upgrade. Apache credited George Chen with discovering the vulnerability and proposing fixes, and published the advisory through the oss-sec mailing list alongside the project’s main site.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-66756 affecting the tika-server unpack endpoint in versions from 4.0.0-alpha-1 up to, but not including, 4.0.0-beta-1, and advised users to upgrade to 4.0.0-beta-1 where the issue is fixed. George Chen was credited with discovering the vulnerability and proposing fixes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.