ZeroHour

CVE-2026-2254

CVSS 3.1
6.3 medium
EPSS
<1%p5
Published
()
Modified
Description

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

Vendors
hitachi
Products
vantara pentaho data integration and analytics
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.