CVE-2026-2253 PUBLISHED

Hitachi Vantara Pentaho Data Integration & Analytics - Improper Restriction of XML External Entity Reference

Assigner: HITVAN
Reserved: 09.02.2026 Published: 27.05.2026 Updated: 27.05.2026

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 7.7

Product Status

Vendor Hitachi Vantara
Product Pentaho Data Integration and Analytics
Versions Default: unaffected
  • affected from 1.0 to 10.2.0.7 (excl.)
  • affected from 10.0 to 11.0.0 (excl.)

Credits

  • Hitachi Group Member finder

References

Problem Types

  • CWE-611 Improper restriction of XML external entity reference CWE

Impacts

  • CAPEC-201 Serialized Data External Linking