CVE-2025-11158
Pentaho Business Analytics Server vulnerability analysis and mitigation

Overview

CVE-2025-11158 is a Missing Authorization (CWE-862) vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics that allows authenticated non-admin users to inject arbitrary Groovy scripts into PRPT reports, leading to remote code execution (RCE). Affected versions include all releases before 10.2.0.6, specifically including the 9.3.x and 8.3.x branches. The vulnerability was published on March 9–10, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) (Red Hat CVE, Pentaho Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) on the Groovy scripting capability within PRPT (Pentaho Report) files published by users. The platform fails to restrict which users can embed and execute Groovy scripts in newly published reports, effectively bypassing the authorization controls introduced to address the related CVE-2022-43938. An attacker with any valid (non-admin) user account can craft a malicious PRPT report containing arbitrary Groovy code and publish it to the server; when the report is rendered or executed, the embedded script runs with server-level privileges. A technical write-up and proof-of-concept details are available from OX Security (OX Security Blog).

Impact

Successful exploitation grants an attacker full remote code execution on the Pentaho server, resulting in high confidentiality, integrity, and availability impact with a changed scope — meaning the compromise can extend beyond the application itself to the underlying host. Attackers can exfiltrate sensitive business intelligence data, tamper with reports and data pipelines, install persistent backdoors, and use the compromised server as a pivot point for lateral movement within the enterprise network. Over 2,600 publicly exposed Pentaho instances are estimated to be vulnerable (OX Security Blog, Red Hat CVE).

Exploitability

Exploitation requires only a valid (non-admin) user account on the Pentaho platform, making the attack accessible to any business user with login credentials. OX Security has published a technical blog post that serves as a proof-of-concept reference, and exploitation has been reported in the wild by multiple sources (OX Security Blog). The EPSS score is approximately 0.036% (0.000360), indicating a currently low but non-zero probability of automated exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog based on available data.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Pentaho Data Integration & Analytics instances (versions before 10.2.0.6) using tools like Shodan or Censys, searching for Pentaho login pages or API endpoints. Over 2,600 such instances are reportedly exposed publicly.
  2. Obtain credentials: Acquire any valid non-admin user account on the target Pentaho instance — this could be through phishing, credential stuffing, or use of a legitimately provisioned business user account.
  3. Craft malicious PRPT report: Create a Pentaho Report (PRPT) file that embeds a malicious Groovy script. The script can execute OS commands, establish a reverse shell, or exfiltrate data (e.g., using Runtime.exec() or similar Groovy/Java constructs).
  4. Publish the report: Log in to the Pentaho web interface and publish the crafted PRPT report to the server. The missing authorization check allows non-admin users to complete this action without restriction.
  5. Trigger execution: Open or schedule the malicious report via the Pentaho interface. When the report is rendered, the embedded Groovy script executes server-side with the privileges of the Pentaho application process.
  6. Achieve objectives: Use the resulting RCE to establish persistence, exfiltrate data, pivot to internal systems, or deploy additional payloads (OX Security Blog).

Indicators of compromise

  • Logs: Pentaho server logs showing non-admin users publishing new PRPT reports, especially from unusual accounts or at unusual times; Groovy script execution events in application logs; unexpected Java process spawning OS-level commands.
  • File System: Newly created or modified .prpt files in the Pentaho repository containing Groovy script blocks; unexpected files (web shells, binaries) written to the server filesystem by the Pentaho process.
  • Network: Outbound connections from the Pentaho server to unknown external IPs or C2 infrastructure, particularly initiated by the Java/Pentaho process; unusual DNS lookups from the server.
  • Process: Child processes spawned by the Pentaho JVM (e.g., cmd.exe, /bin/bash, curl, wget, powershell) that are not part of normal Pentaho operations.
  • Application: Audit logs showing report publication events by non-admin users; reports with embedded script content that were not present before the suspected compromise window (OX Security Blog).

Mitigation and workarounds

The primary remediation is to upgrade Hitachi Vantara Pentaho Data Integration & Analytics to version 10.2.0.6 or later, which introduces proper authorization controls on Groovy script execution in PRPT reports (Pentaho Advisory). As interim workarounds: restrict non-admin user permissions to prevent creation or publication of PRPT reports; implement network-level access controls (firewall rules, VPN requirements) to limit exposure of Pentaho instances to the internet. Additionally, audit all existing PRPT reports in the repository for potentially malicious embedded Groovy scripts, and monitor for suspicious report creation and execution activity.

Community reactions

OX Security published a detailed technical blog post on the vulnerability, noting that it bypasses the fix for the previously disclosed CVE-2022-43938 and that over 2,600 Pentaho instances are publicly exposed (OX Security Blog). The vulnerability received attention on social media platforms including Bluesky and Mastodon, with security community accounts highlighting the critical severity and active exploitation reports. Red Hat also tracked the CVE, reflecting broader industry awareness beyond Hitachi's direct customer base (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Pentaho Business Analytics Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11158CRITICAL9.1
  • Pentaho Business Analytics Server logoPentaho Business Analytics Server
  • cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server
NoYesMar 10, 2026
CVE-2022-4815HIGH8.8
  • Pentaho Business Analytics Server logoPentaho Business Analytics Server
  • cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server
NoYesMay 24, 2023
CVE-2022-4771MEDIUM6.1
  • Pentaho Business Analytics Server logoPentaho Business Analytics Server
  • cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server
NoYesApr 03, 2023
CVE-2023-1158MEDIUM4.3
  • Pentaho Business Analytics Server logoPentaho Business Analytics Server
  • cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server
NoYesMay 24, 2023
CVE-2022-4770MEDIUM4.3
  • Pentaho Business Analytics Server logoPentaho Business Analytics Server
  • cpe:2.3:a:hitachi:vantara_pentaho_business_analytics_server
NoYesApr 03, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management