CVE-2026-2255 PUBLISHED

Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials

Assigner: HITVAN
Reserved: 09.02.2026 Published: 27.05.2026 Updated: 27.05.2026

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Hitachi Vantara
Product Pentaho Data Integration and Analytics
Versions Default: unaffected
  • affected from 1.0 to 10.2.0.6 (excl.)
  • affected from 10.0 to 11.0.0 (excl.)

Credits

  • Hitachi Group Member finder

References

Problem Types

  • CWE-522: Insufficiently Protected Credentials CWE

Impacts

  • CAPEC-102 Session Sidejacking