---
id: CVE-2026-8066
title: >-
  A directory traversal vulnerability in the file upload functionality of
  Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite
  arbitrary files on the device file system
summary: >-
  A directory traversal vulnerability in the file upload functionality of
  Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite
  arbitrary files on the device file system. Depending on the files affected,
  successful…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-23
vendor: Hitachi Energy
product: RTU500 series CMU firmware
affected:
  - rtu500_series_cmu_firmware >= 9.0 < 12.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:17:13.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8066'
references:
  - url: >-
      https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch
    label: cybersecurity@hitachienergy.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T09:30:49.083Z'
---

## Overview

A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
