CVE-2026-2253

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:*

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Las versiones de Hitachi Vantara Pentaho Data Integration & Analytics anteriores a 10.2.0.7 y 11.0.0.0, incluyendo 9.3.x y 8.3.x, no impiden que ciertos analizadores XML resuelvan entidades externas.

18 Jun 2026, 17:04

Type Values Removed Values Added
First Time Hitachi
Hitachi vantara Pentaho Data Integration And Analytics
References () https://support.pentaho.com/hc/en-us/articles/45677548193933--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Improper-Restriction-of-XML-External-Entity-Reference-Versions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2026-2253 - () https://support.pentaho.com/hc/en-us/articles/45677548193933--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Improper-Restriction-of-XML-External-Entity-Reference-Versions-before-10-2-0-7-and-11-0-0-0-Impacted-CVE-2026-2253 - Vendor Advisory
CPE cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*
cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:*

27 May 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-27 04:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-2253

Mitre link : CVE-2026-2253

CVE.ORG link : CVE-2026-2253


JSON object : View

Products Affected

hitachi

  • vantara_pentaho_data_integration_and_analytics
CWE
CWE-611

Improper Restriction of XML External Entity Reference