Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Summary
| CVE | CVE-2026-2255 |
|---|---|
| State | PUBLISHED |
| Assigner | HITVAN |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-27 04:16:26 UTC |
| Updated | 2026-05-27 19:55:50 UTC |
| Description | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.000250000 probability, percentile 0.075690000 (date 2026-06-01)
Problem Types: CWE-522 | CWE-522 CWE-522: Insufficiently Protected Credentials
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Hitachi Vantara | Pentaho Data Integration And Analytics | affected 1.0 10.2.0.6 maven | Not specified |
| CNA | Hitachi Vantara | Pentaho Data Integration And Analytics | affected 10.0 11.0.0 maven | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pe... | [email protected] | support.pentaho.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Hitachi Group Member (en)
There are currently no legacy QID mappings associated with this CVE.