CVE-2026-2072
8.2Hitachi · Infrastructure Analytics Advisor, Ops Center Analyzer
Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer contain a stored cross-site scripting (XSS) vulnerability allowing for unauthorized script execution in the context of a user session.
Executive summary
A high-severity cross-site scripting vulnerability in Hitachi Infrastructure Analytics Advisor and Ops Center Analyzer poses a significant risk of session hijacking and unauthorized data access.
Vulnerability
This is a cross-site scripting (CWE-79) vulnerability where an authenticated attacker can inject malicious scripts into the web interface. Given the CVSS vector (PR:L/UI:R), the attack requires a logged-in user with low privileges to interact with a crafted payload, leading to potential compromise of the user session.
Business impact
The vulnerability carries a CVSS score of 8.2, reflecting a high potential for impact on confidentiality and integrity. Successful exploitation could allow an attacker to hijack administrative or user sessions, potentially leading to unauthorized data exfiltration or unauthorized actions within the management console. Given the nature of these infrastructure management tools, the risk to operational environment visibility and control is substantial.
Remediation
Immediate Action: Update Hitachi Ops Center Analyzer to version 11.0.5-00 or later, and consult the official Hitachi security advisory for specific guidance regarding the Infrastructure Analytics Advisor probe component.
Proactive Monitoring: Review web server and application access logs for suspicious input patterns or unusual JavaScript-like strings in request parameters.
Compensating Controls: Implement a strict Content Security Policy (CSP) and ensure that a Web Application Firewall (WAF) is configured to inspect and block common XSS attack vectors directed at the management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing affected Hitachi infrastructure management solutions must prioritize the application of the vendor-supplied updates. Due to the high severity score and the potential for session-based attacks in management consoles, prompt patching is required to ensure the security of administrative environments.