PatchSiren cyber security CVE debrief
CVE-2026-2460 Hitachi Energy CVE debrief
CVE-2026-2460 is a medium-severity authorization issue in Hitachi Energy Relion REB500. According to the CISA-republished Hitachi Energy advisory, a low-privileged authenticated user may use the DAC protocol to access and alter directory content without being authorized to do so. The vendor remediation is to update to version 8.3.3.1.
- Vendor
- Hitachi Energy
- Product
- Relion REB500
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-24
- Original CVE updated
- 2026-03-03
- Advisory published
- 2026-02-24
- Advisory updated
- 2026-03-03
Who should care
Organizations running Hitachi Energy Relion REB500, especially OT/ICS administrators, security teams, and identity/access-control owners responsible for authenticated user permissions and directory access.
Technical summary
The advisory describes an authorization bypass-style condition: an authenticated user with low-level privileges can access and modify directories using the DAC protocol beyond their intended permissions. CISA lists the issue with CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N (score 6.8), indicating network reachability, low privileges required, and high confidentiality/integrity impact. The provided remediation is to update to Relion REB500 version 8.3.3.1 and apply the vendor's general mitigation factors.
Defensive priority
Medium. Prioritize if REB500 is exposed to broad authenticated access, shared operator accounts, or environments where directory integrity affects operational safety or configuration control.
Recommended defensive actions
- Update Hitachi Energy Relion REB500 to version 8.3.3.1 as recommended by the advisory.
- Restrict authenticated low-privilege accounts to only the minimum DAC and directory access they require.
- Review directory permissions, role assignments, and any workflows that rely on DAC protocol access.
- Monitor for unexpected directory changes or authorization anomalies involving REB500 management paths.
- Apply the vendor's general mitigation factors and CISA recommended industrial control system defensive practices.
Evidence notes
Source evidence comes from CISA CSAF advisory ICSA-26-062-02 for CVE-2026-2460, published 2026-02-24 and republished by CISA on 2026-03-03 as an initial republication of Hitachi Energy PSIRT advisory 8DBD000217. The advisory text states that an authenticated user with low-level privileges may access and alter directory content via the DAC protocol without authorization. The supplied enrichment marks this as not in CISA KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-2460 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-2460
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-2460 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2460
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-062-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.