CVE-2025-11158Disclosure(hitachi / vantara_pentaho_data_integration_and_analytics)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of arbitrary scripts and leading to a RCE.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vantara_pentaho_data_integration_and_analytics

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-03-10)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
vantara_pentaho_data_integration_and_analytics

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-09: 1Mentions · 2026-03-10: 4PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-10: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 403-0903-10
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-091
Disclosure1
2026-03-104
Disclosure4
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-11158: CRITICAL] Attention! Hitachi Vantara Pentaho Data Integration & Analytics versions under 10.2.0.6 are at risk of Remote Code Execution due to unrestricted Groovy scripts in reports. Update A...#cve,CVE-2025-11158,#cybersecurity https://cvefind.com/CVE-2025-11158

    Post summary

    A critical RCE vulnerability (CVE‑2025‑11158) in Hitachi Vantara Pentaho Data Integration & Analytics before version 10.2.0.6 is disclosed, highlighting the need for an update.

    00002247
    601 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-11158 Remote Code Execution in Hitachi Vantara Pentaho Before Version 10.2.0.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-11158

    Post summary

    A new RCE vulnerability (CVE‑2025‑11158) affecting Hitachi Vantara Pentaho versions prior to 10.2.0.6 is announced, with no proof‑of‑concept, exploit, active‑exploitation, patch, or false‑positive information provided.

    00000162
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-11158 - Critical Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing ... https://www.thehackerwire.com/vulnerability/CVE-2025-11158/ https://t.co/fIRGUK803d

    Post summary

    CVE-2025-11158 is a disclosed vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics that allows unrestricted Groovy scripts in user‑created PRPT reports, but no PoC, exploit code, active exploitation, or patch information is provided.

    00000248
    133 followersView on X
  • Moshe Siman Tov Bustan@MosheTov
    Disclosure

    We've discovered a new RCE on Pentaho! CVSS 9.1 CVE-2025-11158 One report upload leads to full system takeover! https://www.ox.security/blog/cve-2025-11158 https://t.co/5hjWlUWMww

    Post summary

    A critical RCE (CVE‑2025‑11158) in Pentaho has been disclosed with a CVSS score of 9.1, where a single report upload can take over the system. No patch or exploit code is included, but a blog post link is provided.

    00000109
    80 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-11158: Hitachi Vantara Pentaho Data Int... Groovy script injection in PRPT reports = instant RCE for any authenticated user - Pentaho shops running <10.2.0.6 are ... https://zerodaysignal.com/vulnerability/CVE-2025-11158 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2025‑11158, describing a Groovy script injection in Pentaho Data Integration that gives authenticated users instant RCE on versions below 10.2.0.6, and links to detailed vulnerability information.

    00000112
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphitachivantara_pentaho_data_integration_and_analytics---

Explore more