CVE-2026-2460
A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.28%
- CWE
- CWE-267
- Published
- 2026-02-24
- Last modified
- 2026-03-12
Affected products
- Hitachi Energy Relion REB500
Weakness type
Related vulnerabilities
- CVE-2026-18858 — IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH []
- CVE-2026-81161 — Content Moderation Notifications - Moderately critical - Access bypass - SA-CONTRIB-2026-107
- CVE-2025-36255 — DS8900F and DS8A00 Privilege Escalation
- CVE-2026-10090 — Multicluster-operators-subscription: multicluster-operators-subscription: namespace edit user can deploy cluster-scoped clusterrolebinding and become cluster-admin via application subscription
- CVE-2026-6816 — TFA Basic Plugins - Access Bypass
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-42406 — BIG-IP and BIG-IQ privilege escalation vulnerability
- CVE-2026-27314 — Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass