CVE-2026-2254: Hitachi Vantara Pentaho Data Integration & Analytics - Incorrect Permission Assignment for Critical Resource
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hitachi Vantara Pentaho Data Integration & Analyticsto a version that resolves this vulnerability.Fixed in 10.2.0.6 - Upgrade
Upgrade
Hitachi Vantara Pentaho Data Integration & Analyticsto a version that resolves this vulnerability.Fixed in 11.0.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2254?
CVE-2026-2254 has a medium severity rating of 6.3.
How do I fix CVE-2026-2254?
To fix CVE-2026-2254, upgrade to Hitachi Vantara Pentaho Data Integration & Analytics versions 10.2.0.6 or 11.0.0.0.
What is CVE-2026-2254 about?
CVE-2026-2254 involves incorrect permission assignments for critical resources in certain API endpoints related to platform mail notifications.
Which versions are affected by CVE-2026-2254?
CVE-2026-2254 affects versions of Hitachi Vantara Pentaho Data Integration & Analytics before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x.
What impact does CVE-2026-2254 have on security?
The impact of CVE-2026-2254 can lead to unauthorized access due to inadequate access control lists applied to certain API endpoints.