CVE-2026-9852
Received Received - Intake

CSV Injection Vulnerability in SYS600 Log Export

Vulnerability report for CVE-2026-9852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Hitachi Energy

Description

A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hitachi_energy sys600 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1236 The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-9852 is a CSV injection vulnerability in SYS600. Attackers can inject malicious formulas into spreadsheets, allowing them to modify data, insert links, or exfiltrate information. In some cases, it may even execute malicious code on the user's machine depending on their environment configuration.

Detection Guidance

Detecting CSV injection vulnerabilities in SYS600 requires monitoring for malicious formulas in exported logs or spreadsheets. Check exported CSV files for unusual formulas starting with =, +, -, @, or containing functions like EXEC, IMPORT, or malicious links. Review log files for arbitrary log messages that could inject formulas.

Impact Analysis

This vulnerability affects all Windows users who can run the Notify service and export logs. Attackers could manipulate exported data, steal sensitive information, or run arbitrary code on your machine if the environment is misconfigured.

Mitigation Strategies

Disable the Notify service if not required. Restrict write permissions to log directories. Implement input validation to prevent arbitrary log messages. Use CSV sanitization tools to remove or neutralize formulas during export. Update SYS600 to the latest patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart