Executive brief
Hitachi Vantara Pentaho Data Integration & Analytics, a platform used for data orchestration and business intelligence, contains a vulnerability that exposes Hadoop cluster credentials in plain text. An authorized user could view these sensitive credentials through a specific testing interface, potentially allowing them to access data or resources outside of their intended permissions. While the impact is limited because the user typically already has rights to run jobs on the cluster, the exposure of plain-text passwords remains a security risk.
Technical details
A vulnerability classified as Insufficiently Protected Credentials (CWE-522) exists in the Cluster Test API of Hitachi Vantara Pentaho Data Integration & Analytics. The API returns Hadoop cluster credentials in plain text to the authenticated user. While the vulnerability requires network access and low-level authentication (PR:L), it allows for the disclosure of sensitive authentication material. The risk is partially mitigated by the fact that users with access to this API typically already possess the authority to submit jobs to the backend using the same credentials. The issue is resolved in versions 10.2.0.6 and 11.0.0.0.
Affected products
- Hitachi Vantara Pentaho Data Integration & Analytics 8.3.x, 9.3.x, < 10.2.0.6, < 11.0.0.0
Timeline
- 2026-05-27: advisory: Initial publication of CVE-2026-2255 and vendor advisory.