CVE-2026-8067
Received Received - Intake

Improper Authorization in RTU500 Web Application Leads to Reboot

Vulnerability report for CVE-2026-8067, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Hitachi Energy

Description

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hitachi_energy rtu500 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authorization issue in the RTU500’s web application. An authenticated user can exploit it to trigger a device reboot via the reset endpoint. This could lead to temporary unavailability and disruption of the device's normal operation.

Detection Guidance

To detect this vulnerability, monitor network traffic for unauthorized reboot requests to RTU500 devices. Check web application logs for repeated access to the reset endpoint by authenticated users. Inspect system logs for unexpected device reboots.

Impact Analysis

If exploited, this vulnerability could cause temporary unavailability of the RTU500 device, disrupting its intended operation. This may lead to operational downtime or loss of control over the device.

Compliance Impact

This vulnerability could lead to temporary device unavailability, which may disrupt operations handling sensitive data. For GDPR, this could impact availability of personal data processing systems. For HIPAA, it may affect the integrity and availability of protected health information systems. However, specific compliance impacts depend on system configuration and use case.

Mitigation Strategies

Restrict access to the RTU500's web application reset endpoint to authorized users only. Monitor network traffic for unauthorized reboot requests. Apply vendor patches or updates if available from Hitachi Energy.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8067. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart