CVE-2026-78314: DIAEnergie - SQL Injection
Published Aug 24, 2026
·Updated
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
Affected Software
1 affected component
DIAEnergie Delta DIAEnergie=1.11.00.002
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta DIAEnergieto a version that resolves this vulnerability.Fixed in 1.11.00.022
Event History
Aug 24, 2026
CVE Published
via MITRE·09:33 AM
Data Sourced
via MITRE·09:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates the attacker can exploit it over the network with low privileges. No user interaction is required.
2
What is the potential impact of successful exploitation?
The vulnerability is described as allowing remote code execution. The CVSS metrics also indicate high impact to confidentiality, integrity, and availability.