← All Advisories

CVE-2026-9852

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-9852

Key Details

CVECVE-2026-9852
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-09
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsHitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600
Classified asCWE-1236 (Improper Neutralization of Formula Elements in a CSV File)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Hitachi Energymicroscada_x_sys600
Hitachi EnergyMicroSCADA SYS600
SubsystemsGeneral OT
SectorsMultiple

What to Know

A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log. (NVD)

What to Do

Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-9852
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-9852
Vendor advisoryhttps://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch