CVE-2026-9852

HIGH

A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user ha...

Affects 0 products across 1 vendor.

CVSS 3.17.8
CVSS v44.6
EPSS0.2%
Percentile10th
PatchUnknown
CVSS Vector — Plain English Requires local access, low complexity, no authentication required, requires user interaction, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-1236: CWE-1236
◆ AI Analysis — automated analysis, not human-reviewed

A unscored severity vulnerability (CVE-2026-9852) affects the target system. A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious cod...

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-9852?
A unscored severity vulnerability (CVE-2026-9852) affects the target system. A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious cod...
What is the CVSS score for CVE-2026-9852?
CVE-2026-9852 has CVSS 7.8 (High). Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. EPSS: 0.2%.
Is CVE-2026-9852 actively exploited?
No confirmed active exploitation of CVE-2026-9852 as of 2026-09-25.
How do I remediate CVE-2026-9852?
Apply vendor patches for CVE-2026-9852. Monitor Hitachienergy advisories.
What systems are affected by CVE-2026-9852?
CVE-2026-9852 affects: Hitachienergy.
Vulnerability Details
CVE IDCVE-2026-9852
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published2026-09-03
Last Modified2026-09-09
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Hitachienergy — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 25 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Hitachienergy
CVE-2024-2013 10.0 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / ... CVE-2019-18253 10.0 An attacker could use specially crafted paths in a specific request to read o... CVE-2021-40342 9.8 In the DES implementation, the affected product versions use a default key f... CVE-2018-14805 9.8 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP... CVE-2019-5620 9.8 ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Mi...
View all Hitachienergy CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →