
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11158 is a Missing Authorization (CWE-862) vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics that allows authenticated non-admin users to inject arbitrary Groovy scripts into PRPT reports, leading to remote code execution (RCE). Affected versions include all releases before 10.2.0.6, specifically including the 9.3.x and 8.3.x branches. The vulnerability was published on March 9–10, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) (Red Hat CVE, Pentaho Advisory).
The root cause is a missing authorization check (CWE-862) on the Groovy scripting capability within PRPT (Pentaho Report) files published by users. The platform fails to restrict which users can embed and execute Groovy scripts in newly published reports, effectively bypassing the authorization controls introduced to address the related CVE-2022-43938. An attacker with any valid (non-admin) user account can craft a malicious PRPT report containing arbitrary Groovy code and publish it to the server; when the report is rendered or executed, the embedded script runs with server-level privileges. A technical write-up and proof-of-concept details are available from OX Security (OX Security Blog).
Successful exploitation grants an attacker full remote code execution on the Pentaho server, resulting in high confidentiality, integrity, and availability impact with a changed scope — meaning the compromise can extend beyond the application itself to the underlying host. Attackers can exfiltrate sensitive business intelligence data, tamper with reports and data pipelines, install persistent backdoors, and use the compromised server as a pivot point for lateral movement within the enterprise network. Over 2,600 publicly exposed Pentaho instances are estimated to be vulnerable (OX Security Blog, Red Hat CVE).
Exploitation requires only a valid (non-admin) user account on the Pentaho platform, making the attack accessible to any business user with login credentials. OX Security has published a technical blog post that serves as a proof-of-concept reference, and exploitation has been reported in the wild by multiple sources (OX Security Blog). The EPSS score is approximately 0.036% (0.000360), indicating a currently low but non-zero probability of automated exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog based on available data.
Runtime.exec() or similar Groovy/Java constructs)..prpt files in the Pentaho repository containing Groovy script blocks; unexpected files (web shells, binaries) written to the server filesystem by the Pentaho process.cmd.exe, /bin/bash, curl, wget, powershell) that are not part of normal Pentaho operations.The primary remediation is to upgrade Hitachi Vantara Pentaho Data Integration & Analytics to version 10.2.0.6 or later, which introduces proper authorization controls on Groovy script execution in PRPT reports (Pentaho Advisory). As interim workarounds: restrict non-admin user permissions to prevent creation or publication of PRPT reports; implement network-level access controls (firewall rules, VPN requirements) to limit exposure of Pentaho instances to the internet. Additionally, audit all existing PRPT reports in the repository for potentially malicious embedded Groovy scripts, and monitor for suspicious report creation and execution activity.
OX Security published a detailed technical blog post on the vulnerability, noting that it bypasses the fix for the previously disclosed CVE-2022-43938 and that over 2,600 Pentaho instances are publicly exposed (OX Security Blog). The vulnerability received attention on social media platforms including Bluesky and Mastodon, with security community accounts highlighting the critical severity and active exploitation reports. Red Hat also tracked the CVE, reflecting broader industry awareness beyond Hitachi's direct customer base (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."