Hitachi Vantara · Pentaho Data Integration & Analytics · CVE-2026-2254
**Name of the Vulnerable Software and Affected Versions**
Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 10.2.0.6
Hitachi Vantara Pentaho Data Integration & Analytics versions prior to 11.0.0.0
**Description**
Incorrect permission assignment occurs because Access Control Lists (ACLs), which are sets of rules that define permissions for users or systems to access specific resources, are not applied to certain API endpoints related to platform mail notifications.
**Recommendations**
Update to version 10.2.0.6 or later.
Update to version 11.0.0.0 or later.