{"api_version":"1","generated_at":"2026-10-04T10:18:41+00:00","cve":"CVE-2026-8067","urls":{"html":"https://cve.report/CVE-2026-8067","api":"https://cve.report/api/cve/CVE-2026-8067.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-8067","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-8067"},"summary":{"title":"CVE-2026-8067","description":"An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.","state":"PUBLISHED","assigner":"Hitachi Energy","published_at":"2026-09-29 10:17:13","updated_at":"2026-09-29 21:39:02"},"problem_types":["CWE-862","CWE-862 CWE-862 Missing authorization"],"metrics":[{"version":"3.1","source":"cybersecurity@hitachienergy.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch","name":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch","refsource":"cybersecurity@hitachienergy.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-8067","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8067","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Hitachi Energy","product":"RTU500 series CMU firmware","version":"affected 9.0 12.0 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"8067","cve":"CVE-2026-8067","epss":"0.003240000","percentile":"0.230360000","score_date":"2026-09-29","updated_at":"2026-09-30 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-8067","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-29T15:04:54.700468Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-29T15:05:10.350Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"RTU500 series CMU firmware","vendor":"Hitachi Energy","versions":[{"lessThan":"12.0","status":"affected","version":"9.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation."}],"value":"An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation."}],"impacts":[{"capecId":"CAPEC-595","descriptions":[{"lang":"en","value":"CAPEC-595 Connection Reset"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-29T12:51:51.369Z","orgId":"e383dce4-0c27-4495-91c4-0db157728d17","shortName":"Hitachi Energy"},"references":[{"url":"https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.5.0"}}},"cveMetadata":{"assignerOrgId":"e383dce4-0c27-4495-91c4-0db157728d17","assignerShortName":"Hitachi Energy","cveId":"CVE-2026-8067","datePublished":"2026-09-29T09:33:52.627Z","dateReserved":"2026-05-07T05:51:59.463Z","dateUpdated":"2026-09-29T15:05:10.350Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-29 10:17:13","lastModifiedDate":"2026-09-29 21:39:02","problem_types":["CWE-862","CWE-862 CWE-862 Missing authorization"],"metrics":{"cvssMetricV31":[{"source":"cybersecurity@hitachienergy.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-29T15:04:54.700468Z","id":"CVE-2026-8067","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"8067","Ordinal":"1","Title":"CVE-2026-8067","CVE":"CVE-2026-8067","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"8067","Ordinal":"1","NoteData":"An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.","Type":"Description","Title":"CVE-2026-8067"}]}}}