---
id: CVE-2026-8067
title: >-
  An improper authorization vulnerability in the RTU500’s web application allows
  an authenticated user to trigger the RTU500 to reboot through the reset
  endpoint
summary: >-
  An improper authorization vulnerability in the RTU500’s web application allows
  an authenticated user to trigger the RTU500 to reboot through the reset
  endpoint. Successful exploitation could cause temporary device unavailability
  and disr…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-862
vendor: Hitachi Energy
product: RTU500 series CMU firmware
affected:
  - rtu500_series_cmu_firmware >= 9.0 < 12.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:17:13.397'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8067'
references:
  - url: >-
      https://publisher.hitachienergy.com/preview?DocumentID=8DBD000251&LanguageCode=en&DocumentPartId=&Action=Launch
    label: cybersecurity@hitachienergy.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T10:31:36.315Z'
---

## Overview

An improper authorization vulnerability in the RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could cause temporary device unavailability and disruption of its intended operation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
