Skip to content
Ubuntu Apache Tika Important Info Exposure USN-8717-1 CVE-2026

Ubuntu Apache Tika Important Info Exposure USN-8717-1 CVE-2026

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Apache Tika could be made to expose sensitive information over the network. Software Description: - tika: A content analysis toolkit Details: It was discovered that Apache Tika's ISA-Tab parser incorrectly handled file path resolution. An attacker who could place files in a directory that Tika subsequently parses could use this issue to read arbitrary files accessible to the Tika process and have their contents emitted into the extracted text output.

Apache Tika could be made to expose sensitive information over the

Software Description:

- tika: A content analysis toolkit

It was discovered that Apache Tika's ISA-Tab parser incorrectly handled

file path resolution. An attacker who could place files in a directory that

Tika subsequently parses could use this issue to read arbitrary files

accessible to the Tika process and have their contents emitted into the

extracted text output.

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libtika-java 1.22-2+deb11u1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libtika-java 1.22-1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8717-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)