Executive brief
Hitachi Vantara Pentaho is a platform used by businesses to integrate and analyze large datasets. A security flaw in certain versions allows users with low-level access to bypass security controls on email notification settings. This could allow an unauthorized individual to view or modify system notification configurations, potentially disrupting communications or exposing internal metadata.
Technical details
An incorrect permission assignment (CWE-732) exists in Hitachi Vantara Pentaho Data Integration & Analytics. The application fails to enforce Access Control Lists (ACLs) on specific API endpoints responsible for platform mail notifications. A remote attacker with low-privileged credentials can interact with these endpoints over the network to view or modify notification settings. This vulnerability affects versions prior to 10.2.0.6 and 11.0.0.0, including legacy 8.3.x and 9.3.x branches. Users are advised to upgrade to version 10.2.0.6 or 11.0.0.0 to remediate the issue.
Affected products
- Hitachi Vantara Pentaho Data Integration & Analytics Before 10.2.0.6, 11.0.0.0, 9.3.x, 8.3.x
Timeline
- 2026-05-27: disclosed
- 2026-05-27: advisory