Back to Feed
VulnerabilitiesMar 3, 2026

Hitachi Energy Relion REB500 Product

Hitachi Energy has released a security advisory addressing two vulnerabilities in the Relion REB500 product (versions 8.3.3.0 and prior) that allow authenticated users with specific roles to access and modify unauthorized directory contents. Both CVE-2026-2459 and CVE-2026-2460 are rated MEDIUM severity and affect critical energy infrastructure worldwide, with mitigation available through updating to version 8.3.3.1 or disabling the Installer role.

Summary

Hitachi Energy has released a security advisory addressing two vulnerabilities in the Relion REB500 product (versions 8.3.3.0 and prior) that allow authenticated users with specific roles to access and modify unauthorized directory contents. Both CVE-2026-2459 and CVE-2026-2460 are rated MEDIUM severity and affect critical energy infrastructure worldwide, with mitigation available through updating to version 8.3.3.1 or disabling the Installer role.

Indicators of Compromise

  • cve — CVE-2026-2459
  • cve — CVE-2026-2460