CVE-2026-2459 PUBLISHED

Assigner: Hitachi Energy
Reserved: 13.02.2026 Published: 24.02.2026 Updated: 24.02.2026

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.4

Product Status

Vendor Hitachi Energy
Product Relion REB500
Versions Default: unaffected
  • affected from 8.0.0.0 to 8.3.3.0 (incl.)

References

Problem Types

  • CWE-267 Privilege Defined with Unsafe Actions CWE

Impacts

  • CAPEC-165 File Manipulation