High severity7.7NVD Advisory· Published May 27, 2026· Updated Jul 24, 2026
CVE-2026-2253
CVE-2026-2253
Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
Affected products
4cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*range: <10.2.0.7
- cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:*
- cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:*
- (no CPE)range: <10.2.0.7, <11.0.0.0, 9.3.x, 8.3.x
Patches
Vulnerability mechanics
References
1News mentions
1- Hitachi Discloses Six CVEs Across Pentaho, RTU500, Ops Center, and HiDraw ProductsVypr Intelligence · May 27, 2026