PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-1772 Hitachi Energy CVE debrief

CVE-2026-1772 is a confidentiality issue in the RTU500 web interface. The advisory states that an unprivileged user can read user management information using browser development utilities, even though the data is not exposed through the normal RTU500 web UI. CISA’s advisory assigns CVSS 3.1 4.3/Medium and points to firmware updates as the primary fix.

Vendor
Hitachi Energy
Product
RTU500 series CMU Firmware
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-24
Original CVE updated
2026-03-03
Advisory published
2026-02-24
Advisory updated
2026-03-03

Who should care

Organizations running Hitachi Energy RTU500 series CMU Firmware, especially OT/ICS operators, administrators, and security teams responsible for web-accessible management interfaces.

Technical summary

The source advisory describes an information disclosure in the RTU500 web interface: a low-privilege user can access user management information that should not be available to them through normal UI flows. The issue is network-reachable and requires low privileges, with no integrity or availability impact listed in the provided CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Affected firmware ranges in the advisory are 12.7.1-12.7.7, 13.5.1-13.5.4, 13.6.1-13.6.2, 13.7.1-13.7.7, and 13.8.1.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade to the vendor-fixed firmware version that matches your branch: 12.7.8, 13.7.8 or later, or 13.8.2.
  • Follow the vendor's general mitigation factors/workarounds from the advisory until patching is complete.
  • Review which users have access to the RTU500 web interface and confirm that low-privilege accounts are not used for administrative functions.
  • Apply CISA ICS recommended practices and defense-in-depth guidance for OT environments, including limiting management exposure and enforcing least privilege.

Evidence notes

The source corpus identifies advisory ICSA-26-062-03 / CVE-2026-1772 for the Hitachi Energy RTU500 Product and states that an unprivileged user can read user management information by using browser development utilities. The source also lists the affected CMU firmware ranges and the remediations: 12.7.8, 13.7.8 or latest, and 13.8.2 depending on branch. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-1772 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-1772

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-1772 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1772

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-062-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.