Junglewise Threat Intelligence

CVE-2026-9852: Hitachi Energy SYS600 CSV injection in logs

CVE-2026-9852 · Severity: high · CVSS 7.8 · Published 2026-09-03

Technologies: Hitachi Energy SYS600, Hitachienergy Microscada X Sys600. Vendors: Hitachi Energy, Hitachienergy.

Executive brief

SYS600 is a Hitachi Energy industrial control system product used to manage and monitor power systems. A CSV injection vulnerability allows attackers who can inject malicious formulas into log messages to manipulate spreadsheet data, insert links, exfiltrate sensitive information, or potentially execute arbitrary code when logs are exported and opened in spreadsheet applications. Exploitation requires the ability to create arbitrary log messages through normal functionality, log injection, or the SYS600 broker.

Technical details

This is a CSV injection (formula injection) vulnerability in SYS600's logging functionality. When log data is exported to CSV format, malicious formulas injected into log messages are not sanitized, allowing them to execute when opened in spreadsheet applications like Microsoft Excel. The vulnerability affects Windows users who can run the Notify service and export logs. Attackers must first establish a means to create arbitrary log entries via SCIL scripts, log injection, or the SYS600 broker. Once exported and opened in a spreadsheet application, the injected formulas can modify data, insert hyperlinks for credential theft, exfiltrate data, or achieve remote code execution depending on the victim's spreadsheet application configuration. A patch or mitigation should sanitize log entries before CSV export and disable formula evaluation in exported files.

Affected products

  • Hitachi Energy SYS600 all

Timeline

  • 2026-09-03: disclosed

References

Related threats