CVE-2026-2255
Last modified
CVE-2026-2255 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hitachi | Vantara Pentaho Data Integration And Analytics | < 10.2.0.7 |
| Hitachi | Vantara Pentaho Data Integration And Analytics | > 10.2.0.8, < 11.0.0.0 |
| Hitachi | Vantara Pentaho Data Integration And Analytics | 8.3 |
| Hitachi | Vantara Pentaho Data Integration And Analytics | 9.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2255?
How severe is CVE-2026-2255?
How do I fix CVE-2026-2255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22543The credentials required to access the device's web server a…6.9
- CVE-2026-22544An attacker with a network connection could detect credentia…8.7
- CVE-2026-22545Mattermost versions 10.11.x <= 10.11.10 fail to validate use…3.5
- CVE-2026-22547Gitea versions before 1.25.5 lack validation constraints for…9.1
- CVE-2026-22548When a BIG-IP Advanced WAF or ASM security policy is configu…8.2
- CVE-2026-22549A vulnerability exists in F5 BIG-IP Container Ingress Servic…6.9
- CVE-2026-22550OS command injection vulnerability exists in ELECOM wireless…8.8
- CVE-2026-22551In Eclipse Theia versions prior to 1.71.0, the AI chat rende…6.5
- CVE-2026-22552WebSocket endpoints lack proper authentication mechanisms, e…9.8
- CVE-2026-22553All versions of InSAT MasterSCADA BUK-TS are susceptible to …9.8
- CVE-2026-22554MediaArea MediaInfoLib Channel Splitting heap-based buffer o…7.8
- CVE-2026-22555Gitea versions before 1.26.0 allow API users to fork a repos…8.1
Are you affected by CVE-2026-2255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
