CVE Vulnerabilities

CVE-2026-2253

Improper Restriction of XML External Entity Reference

Published: May 27, 2026 | Modified: Jun 18, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Vantara_pentaho_data_integration_and_analyticsHitachi*10.2.0.7 (excluding)
Vantara_pentaho_data_integration_and_analyticsHitachi10.2.0.8 (excluding)11.0.0.0 (excluding)
Vantara_pentaho_data_integration_and_analyticsHitachi8.3 (including)8.3 (including)
Vantara_pentaho_data_integration_and_analyticsHitachi9.3 (including)9.3 (including)

Potential Mitigations

References