USN-8717-1: Apache Tika vulnerability
It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output.
CSIRTS triage
- What
- Apache Tika's ISA-Tab parser incorrectly resolves file paths, allowing reading of arbitrary files accessible to the Tika process.
- Who is affected
- Systems using Apache Tika to parse ISA-Tab files from untrusted sources or from directories where an attacker can place files.
- Urgency
- Medium to high; an attacker with local file placement capability can exfiltrate sensitive data through the parsed output.
- Action
- Update Apache Tika to a patched version; restrict the ability to place files in directories processed by Tika.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Tika
Get an email when a new Tika advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8717-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-667550.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-66755 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Ubuntu Security Notices
- unknownUSN-8661-4: Linux kernel vulnerabilities2026-09-02
- unknownUSN-8715-1: Linux kernel (Oracle) vulnerabilities2026-09-02
- unknownUSN-8714-1: Linux kernel vulnerabilities2026-09-02
- unknownUSN-8713-1: BioSig vulnerabilities2026-09-02
- unknownUSN-8712-1: pyasn1 vulnerabilities2026-09-01