Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
References
Configurations
Configuration 1 (hide)
|
History
23 Jul 2026, 11:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Jun 2026, 17:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:* cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:* cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:* |
|
| References | () https://support.pentaho.com/hc/en-us/articles/45676384909069--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2254?brand_id=1928686 - Vendor Advisory | |
| First Time |
Hitachi
Hitachi vantara Pentaho Data Integration And Analytics |
27 May 2026, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 04:16
Updated : 2026-07-24 12:10
NVD link : CVE-2026-2254
Mitre link : CVE-2026-2254
CVE.ORG link : CVE-2026-2254
JSON object : View
Products Affected
hitachi
- vantara_pentaho_data_integration_and_analytics
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
