{"api_version":"1","generated_at":"2026-06-02T18:12:39+00:00","cve":"CVE-2026-2255","urls":{"html":"https://cve.report/CVE-2026-2255","api":"https://cve.report/api/cve/CVE-2026-2255.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-2255","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-2255"},"summary":{"title":"Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials","description":"Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.","state":"PUBLISHED","assigner":"HITVAN","published_at":"2026-05-27 04:16:26","updated_at":"2026-05-27 19:55:50"},"problem_types":["CWE-522","CWE-522 CWE-522: Insufficiently Protected Credentials"],"metrics":[{"version":"3.1","source":"security.vulnerabilities@hitachivantara.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2255","name":"https://support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2255","refsource":"security.vulnerabilities@hitachivantara.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-2255","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2255","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Hitachi Vantara","product":"Pentaho Data Integration and Analytics","version":"affected 1.0 10.2.0.6 maven","platforms":[]},{"source":"CNA","vendor":"Hitachi Vantara","product":"Pentaho Data Integration and Analytics","version":"affected 10.0 11.0.0 maven","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Hitachi Group Member","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"2255","cve":"CVE-2026-2255","epss":"0.000250000","percentile":"0.075690000","score_date":"2026-06-01","updated_at":"2026-06-02 00:05:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-2255","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-05-27T18:00:31.690560Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-27T18:00:39.061Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Pentaho Data Integration and Analytics","vendor":"Hitachi Vantara","versions":[{"lessThan":"10.2.0.6","status":"affected","version":"1.0","versionType":"maven"},{"lessThan":"11.0.0","status":"affected","version":"10.0","versionType":"maven"}]}],"credits":[{"lang":"en","type":"finder","value":"Hitachi Group Member"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Hitachi Vantara Pentaho Data Integration &amp; Analytics versions before 10.2.0.6 and 11.0.0.0, including&nbsp;9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although&nbsp;the user should not see those explicitly, the defect is mitigated by the fact the user can already&nbsp;leverage those credentials to submit jobs under the same account through the backend API.&nbsp;<br>"}],"value":"Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API."}],"impacts":[{"capecId":"CAPEC-102","descriptions":[{"lang":"en","value":"CAPEC-102 Session Sidejacking"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-27T02:57:46.206Z","orgId":"dce6e192-ff49-4263-9134-f0beccb9bc13","shortName":"HITVAN"},"references":[{"url":"https://support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2255"}],"source":{"discovery":"INTERNAL"},"title":"Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"dce6e192-ff49-4263-9134-f0beccb9bc13","assignerShortName":"HITVAN","cveId":"CVE-2026-2255","datePublished":"2026-05-27T02:51:31.793Z","dateReserved":"2026-02-09T15:09:09.473Z","dateUpdated":"2026-05-27T18:00:39.061Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-27 04:16:26","lastModifiedDate":"2026-05-27 19:55:50","problem_types":["CWE-522","CWE-522 CWE-522: Insufficiently Protected Credentials"],"metrics":{"cvssMetricV31":[{"source":"security.vulnerabilities@hitachivantara.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"2255","Ordinal":"1","Title":"Hitachi Vantara Pentaho Data Integration & Analytics - Insuffici","CVE":"CVE-2026-2255","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"2255","Ordinal":"1","NoteData":"Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.","Type":"Description","Title":"Hitachi Vantara Pentaho Data Integration & Analytics - Insuffici"}]}}}