CVE-2026-2255: Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hitachi Vantara Pentaho Data Integration & Analyticsto a version that resolves this vulnerability.Fixed in 10.2.0.6 - Upgrade
Upgrade
Hitachi Vantara Pentaho Data Integration & Analyticsto a version that resolves this vulnerability.Fixed in 11.0.0.0 - Compensating control
Mitigate exposure by preventing users from leveraging the exposed Hadoop cluster credentials via the Cluster Test API / backend API under the same account; restrict or isolate access to the Cluster Test API and backend API to authorized users only.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2255?
The severity of CVE-2026-2255 is medium with a score of 4.3.
How do I fix CVE-2026-2255?
To fix CVE-2026-2255, upgrade to Hitachi Vantara Pentaho Data Integration & Analytics versions 10.2.0.6 or 11.0.0.0 or later.
What are the impacted versions in CVE-2026-2255?
CVE-2026-2255 impacts versions of Hitachi Vantara Pentaho Data Integration & Analytics prior to 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x.
What is the nature of the vulnerability in CVE-2026-2255?
CVE-2026-2255 involves insufficiently protected credentials that expose Hadoop cluster credentials in plain text through the Cluster Test API.
Is user interaction required for CVE-2026-2255?
No, user interaction is not required for CVE-2026-2255 as the credentials can be exposed without user visibility.