API Permission Oversight in Hitachi Vantara Pentaho Data Integration & Analytics
CVE-2026-2254
6.3MEDIUM
Key Information:
- Vendor
Hitachi
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-2254?
Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.6 and 11.0.0.0, as well as 9.3.x and 8.3.x, have been found to lack proper access control measures on specific API endpoints concerning platform mail notifications. This oversight allows unauthorized users to potentially access sensitive functionalities without appropriate permissions, leading to security concerns for users relying on these integrations in their workflows.
Affected Version(s)
Pentaho Data Integration and Analytics 1.0 < 10.2.0.6
Pentaho Data Integration and Analytics 10.0 < 11.0.0.0