CVE-2025-11158 PUBLISHED

Hitachi Vantara Pentaho Data Integration & Analytics - Missing Authorization

Assigner: HITVAN
Reserved: 29.09.2025 Published: 09.03.2026 Updated: 09.03.2026

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Hitachi Vantara
Product Pentaho Data Integration and Analytics
Versions Default: unaffected
  • affected from 1.0 to 9.3.* (incl.)
  • affected from 10.0 to 10.2.0.6 (excl.)

Credits

  • Nir Zadok (nirza) and Moshe Siman Tov Bustan from OX Security finder

References

Problem Types

  • CWE-862: Missing Authorization CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs