nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-2459 CVE-2026-2459
HIGH
Hitachi Energy Relion REB500 Installer Role Unauthorized Directory Access
Record summary
CVE-2026-2459 has a selected CVSS score of 7.4 (high).
Description
A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 28, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Relion REB500Browse Hitachi Energy / Relion REB500Default status: unaffected | CVE List | 8.0.0.0 to ≤ 8.3.3.0 | affected |
References
2publisher.hitachienergy.com
https://publisher.hitachienergy.com/preview?DocumentID=8DBD000217&LanguageCode=en&DocumentPartId=&Action=Launch