CVE Explorer
CVE-2026-2255
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Although the user should not see those explicitly, the defect is mitigated by the fact the user can already leverage those credentials to submit jobs under the same account through the backend API.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Pentaho Data Integration and Analytics","vendor":"Hitachi Vantara","versions":[{"lessThan":"10.2.0.6","status":"affected","version":"1.0","versionType":"maven"},{"lessThan":"11.0.0","status":"affected","version":"10.0","versionType":"maven"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:2455b28934c8f3dc165ff800a4bec843af783cb60ef069a2c568ed8008a2da2c · sha256:8fa6368b8493197d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:2455b28934c8f3dc165ff800a4bec843af783cb60ef069a2c568ed8008a2da2c · sha256:8fa6368b8493197d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:2455b28934c8f3dc165ff800a4bec843af783cb60ef069a2c568ed8008a2da2c · sha256:8fa6368b8493197d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://support.pentaho.com/hc/en-us/articles/45672235545101--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2255"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:2455b28934c8f3dc165ff800a4bec843af783cb60ef069a2c568ed8008a2da2c · sha256:8fa6368b8493197d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.