PT-2026-43484 · Hitachi Vantara · Pentaho Data Integration & Analytics

Published

2026-05-27

·

Updated

2026-05-27

·

CVE-2026-2254

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2026-2254

Affected Products

Pentaho Data Integration & Analytics