Improper Restriction of XML External Entity References in Hitachi Vantara Pentaho Data Integration & Analytics
CVE-2026-2253
7.7HIGH
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-2253?
Hitachi Vantara Pentaho Data Integration & Analytics is vulnerable due to inadequate controls over certain XML parsers that permit the resolution of external entities. This flaw can potentially expose sensitive data by allowing attackers to craft malicious XML documents that exploit external entity references. Users should upgrade to the latest versions to mitigate this risk.
Affected Version(s)
Pentaho Data Integration and Analytics 1.0 < 10.2.0.7
Pentaho Data Integration and Analytics 10.0 < 11.0.0