CVE-2026-78308: Authentication Bypass in DIAEnergie
Published Sep 24, 2026
·Updated
Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass.
This issue affects DIAEnergie: before 1.11.00.022.
Affected Software
1 affected component
Delta Electronics DIAEnergie<1.11.00.022
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DIAEnergieto a version that resolves this vulnerability.Fixed in 1.11.00.022
Event History
Sep 24, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which DIAEnergie versions are affected?
DIAEnergie versions before 1.11.00.022 are affected. Version 1.11.00.022 and later are not identified as affected by the provided advisory data.
2
Does exploitation require credentials or user interaction?
No. The supplied CVSS vector indicates network access, low attack complexity, no privileges required, and no user interaction.
3
What impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impact as high. This indicates an attacker who exploits the authentication bypass could potentially compromise all three security properties.