« Volver al listado

CVE-2026-2254

Estado: AnalizadaMedia (6.3)—

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-2254",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-2254",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T17:59:55.849274Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security.vulnerabilities@hitachivantara.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security.vulnerabilities@hitachivantara.com",
      "affectedData": [
        {
          "vendor": "Hitachi Vantara",
          "product": "Pentaho Data Integration and Analytics",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "lessThan": "10.2.0.6",
              "versionType": "maven"
            },
            {
              "status": "affected",
              "version": "10.0",
              "lessThan": "11.0.0.0",
              "versionType": "maven"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-27T04:16:26.693",
  "references": [
    {
      "url": "https://support.pentaho.com/hc/en-us/articles/45676384909069--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Incorrect-Permission-Assignment-for-Critical-Resource-Versions-before-10-2-0-6-and-11-0-0-0-Impacted-CVE-2026-2254?brand_id=1928686",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security.vulnerabilities@hitachivantara.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security.vulnerabilities@hitachivantara.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notfications."
    },
    {
      "lang": "es",
      "value": "Hitachi Vantara Pentaho Data Integration & Analytics versiones anteriores a la 10.2.0.6 y 11.0.0.0, incluyendo las 9.3.x y 8.3.x, no aplica ACLs en ciertos endpoints de la API relacionados con las notificaciones de correo de la plataforma."
    }
  ],
  "lastModified": "2026-07-24T12:10:00.210",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50E55F6A-825B-4C80-BA1C-9EF2B058A230",
              "versionEndExcluding": "10.2.0.7"
            },
            {
              "criteria": "cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42A22CB8-1987-4AAE-8540-63E534FCEE32",
              "versionEndExcluding": "11.0.0.0",
              "versionStartExcluding": "10.2.0.8"
            },
            {
              "criteria": "cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:8.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD5C2274-E0A1-4DD3-BAC8-C107C4026D8B"
            },
            {
              "criteria": "cpe:2.3:a:hitachi:vantara_pentaho_data_integration_and_analytics:9.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D8EFD76-9B82-47CF-95F7-5117C58706EB"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security.vulnerabilities@hitachivantara.com"
}