CSV Injection Vulnerability in SYS600 by Hitachi Energy
CVE-2026-9852

4.6MEDIUM

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
3 September 2026

What is CVE-2026-9852?

A vulnerability exists in SYS600 that allows an attacker to exploit CSV injection techniques. This can result in malicious formulas being introduced into exported spreadsheets, potentially allowing data modification, link insertion, and data exfiltration. Depending on user environment configurations, this flaw may also enable execution of malicious code on the user's machine. Attackers can exploit this vulnerability through methods such as SCIL scripts, log injection vulnerabilities, or via the SYS600 broker, affecting all Windows users capable of running the Notify service and exporting logs.

Affected Version(s)

MicroSCADA SYS600 10.0 <= 10.7

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.