Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient Authorization Allows Low‑Privilege User to Alter Directories via DAC Protocol |
Sat, 28 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy reb500
Hitachienergy reb500 Firmware |
|
| CPEs | cpe:2.3:h:hitachienergy:reb500:-:*:*:*:*:*:*:* cpe:2.3:o:hitachienergy:reb500_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Hitachienergy reb500
Hitachienergy reb500 Firmware |
|
| Metrics |
cvssV3_1
|
Wed, 25 Feb 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy
Hitachienergy relion Reb500 |
|
| Vendors & Products |
Hitachienergy
Hitachienergy relion Reb500 |
Tue, 24 Feb 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so. | |
| Weaknesses | CWE-267 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2026-02-28T02:23:18.377Z
Reserved: 2026-02-13T11:08:27.300Z
Link: CVE-2026-2460
Updated: 2026-02-28T02:23:13.406Z
Status : Analyzed
Published: 2026-02-24T14:16:23.647
Modified: 2026-02-26T18:04:30.317
Link: CVE-2026-2460
No data.
OpenCVE Enrichment
Updated: 2026-04-16T16:30:15Z