Improper Restriction of XML External Entity References in Hitachi Vantara Pentaho Data Integration & Analytics
CVE-2026-2253

7.7HIGH

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
27 May 2026

What is CVE-2026-2253?

Hitachi Vantara Pentaho Data Integration & Analytics is vulnerable due to inadequate controls over certain XML parsers that permit the resolution of external entities. This flaw can potentially expose sensitive data by allowing attackers to craft malicious XML documents that exploit external entity references. Users should upgrade to the latest versions to mitigate this risk.

Affected Version(s)

Pentaho Data Integration and Analytics 1.0 < 10.2.0.7

Pentaho Data Integration and Analytics 10.0 < 11.0.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hitachi Group Member
.