CVE-2026-2459Disclosure(hitachienergy / reb500)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-267

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • reb500
  • reb500_firmware

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-28); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
reb500reb500_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-26: 1Mentions · 2026-02-28: 3Mentions · 2026-03-01: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-28: 3Technical Details · 2026-03-01: 102-2602-2803-01
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-261
Disclosure1
2026-02-283
Disclosure3
2026-03-011
Disclosure1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2459 (CVSS:7.4, HIGH) is Undergoing Analysis. A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of direc..https://nvd.nist.gov/vuln/detail/CVE-2026-2459 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2459, a high‑severity vulnerability in REB500 that allows authenticated Installer users to read and modify directory contents, with CVSS 7.4, but no PoC, exploit, or patch details are provided.

    0000023
    173 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2459 A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so. https://www.cve.org/CVERecord?id=CVE-2026-2459 ----- Traducción: CVE-2026-2459 Exist… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2459, describing a privilege escalation flaw in REB500 that allows Installer role users to modify unauthorized directories, with a link to the CVE record.

    0000041
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2459 A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so. https://www.cve.org/CVERecord?id=CVE-2026-2459

    Post summary

    CVE-2026-2459 exposes a privilege escalation flaw in REB500, allowing authenticated Installer‑role users to read and modify directories beyond their authorized scope.

    00000430
    56.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2459 (CVSS:7.4, HIGH) is Undergoing Analysis. A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of direc..https://nvd.nist.gov/vuln/detail/CVE-2026-2459 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑2459 affecting REB500, noting that an authenticated Installer role can modify directory contents. No proof of concept, exploit code, or patch is referenced.

    0000032
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2459 - High A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so. https://www.thehackerwire.com/vulnerability/CVE-2026-2459/ https://t.co/CenkS4JPzP

    Post summary

    A high severity vulnerability in REB500 allows authenticated users with the Installer role to access and modify directories they are not authorized to, indicating a privilege escalation flaw.

    0000038
    119 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWhitachienergyreb500---
OShitachienergyreb500_firmware---

Explore more