CVE-2026-2254 PUBLISHED

Hitachi Vantara Pentaho Data Integration & Analytics - Incorrect Permission Assignment for Critical Resource

Assigner: HITVAN
Reserved: 09.02.2026 Published: 27.05.2026 Updated: 27.05.2026

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 6.3

Product Status

Vendor Hitachi Vantara
Product Pentaho Data Integration and Analytics
Versions Default: unaffected
  • affected from 1.0 to 10.2.0.6 (excl.)
  • affected from 10.0 to 11.0.0.0 (excl.)

Credits

  • Hitachi Group Member finder

References

Problem Types

  • CWE-732 Incorrect Permission Assignment for Critical Resource CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs