PT-2026-43483 · Hitachi Vantara · Pentaho Data Integration & Analytics

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-2253

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-2253

Affected Products

Pentaho Data Integration & Analytics