Status: UPDATED | Advisory ID: CVE-2026-9852
| CVE | CVE-2026-9852 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-09 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Hitachi Energy microscada_x_sys600 and Hitachi Energy MicroSCADA SYS600 |
| Classified as | CWE-1236 (Improper Neutralization of Formula Elements in a CSV File) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Hitachi Energy | microscada_x_sys600 | ||
| Hitachi Energy | MicroSCADA SYS600 |
| Subsystems | General OT |
| Sectors | Multiple |
A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log. (NVD)
Monitor Hitachi Energy's web page for any future patch releases. See vendor advisory link below.