VYPR
Medium severity6.3NVD Advisory· Published May 27, 2026· Updated Jul 24, 2026

CVE-2026-2254

CVE-2026-2254

Description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Affected products

5
  • Range: <10.2.0.6 || <11.0.0.0
  • cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*range: <10.2.0.7
    • cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:*
    • cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:*
    • (no CPE)range: <10.2.0.6, <11.0.0.0, 9.3.x, 8.3.x

Patches

Vulnerability mechanics

References

1

News mentions

1