CVE-2026-78309: SQL Injection in DIAEnergie
Published Sep 24, 2026
·Updated
SQL Injection vulnerability in DIAEnergie.
This issue affects DIAEnergie: before 1.11.00.022.
Affected Software
1 affected component
Delta Electronics DIAEnergie<1.11.00.022
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DIAEnergieto a version that resolves this vulnerability.Fixed in 1.11.00.022
Event History
Sep 24, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires low privileges, has low attack complexity, and does not require user interaction. Successful exploitation can affect confidentiality, integrity, and availability.
2
How can I determine whether an installation is affected, and what is the remediation?
DIAEnergie versions earlier than 1.11.00.022 are affected. Identify the installed DIAEnergie version and upgrade affected systems to 1.11.00.022 or later.