← All Advisories

CVE-2026-8066

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-8066

Key Details

CVECVE-2026-8066
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-29
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productsHitachi Energy RTU500 series CMU firmware
Classified asCWE-23 (Relative Path Traversal)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi EnergyRTU500 series CMU firmware
SubsystemsGeneral OT
SectorsMultiple

What to Know

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8066
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8066