CVE-2026-2459: High severity hitachienergy Reb500 Firmware vulnerability
Published Feb 24, 2026
·Updated
A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.
Affected Software
2 affected components
All of the following
hitachienergy Reb500 Firmware<=8.3.3.0
hitachienergy reb500
Event History
Feb 24, 2026
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
DescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Nov 4, 58232
Event
via NVD·07:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-2459?
CVE-2026-2459 has a medium severity rating due to potential unauthorized access to sensitive directory contents.
2
How do I fix CVE-2026-2459?
To fix CVE-2026-2459, ensure that proper access controls are enforced for authenticated users with the Installer role.
3
Who is affected by CVE-2026-2459?
CVE-2026-2459 affects users with the Installer role in the REB500 firmware versions up to 8.3.3.1.
4
Can CVE-2026-2459 be exploited remotely?
CVE-2026-2459 requires an authenticated user, so it cannot be exploited remotely without valid credentials.
5
What are the consequences of exploiting CVE-2026-2459?
Exploiting CVE-2026-2459 may allow unauthorized users to alter directory contents, potentially compromising system integrity.