CVE-2026-78315: DIAEnergie - SQL Injection
Published Aug 24, 2026
·Updated
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
Affected Software
1 affected component
DIAEnergie Delta DIAEnergie=1.11.00.002
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Delta DIAEnergieto a version that resolves this vulnerability.Fixed in 1.11.00.022
Event History
Aug 24, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs low-level privileges and network access. Exploitation is rated low complexity and does not require user interaction.
2
What is the potential security impact if exploitation succeeds?
Successful exploitation can result in high impact to confidentiality, integrity, and availability, with potential remote code execution. The vulnerability's scope is unchanged.