CVE-2026-78309
8.8Deltaww · DIAEnergie
A SQL injection vulnerability exists in Deltaww DIAEnergie software, allowing authenticated attackers to execute arbitrary SQL commands.
Executive summary
A high-severity SQL injection vulnerability in Deltaww DIAEnergie allows authenticated users to compromise database integrity and confidentiality.
Vulnerability
This is a SQL injection flaw (CWE-89) in DIAEnergie that allows an authenticated user to perform unauthorized database operations. The vulnerability is triggered via the network with low attack complexity, requiring low privileges to execute.
Business impact
The ability to perform SQL injection poses a significant risk to the confidentiality, integrity, and availability of the affected system. An attacker could extract sensitive data, modify application records, or potentially gain full control over the backend database. Given the CVSS score of 8.8, this vulnerability represents a high-risk entry point for lateral movement or data exfiltration within the operational network.
Remediation
Immediate Action: Contact Delta technical support to obtain and upgrade to DIAEnergie version 1.11.00.022 or a later version.
Proactive Monitoring: Review database access logs for unusual query patterns, such as unexpected syntax or large data exports, which may indicate exploitation attempts.
Compensating Controls: Implement a Web Application Firewall (WAF) with SQL injection protection rules to inspect and block malicious payloads directed at the DIAEnergie interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a substantial risk to organizational data integrity due to the potential for unauthorized database manipulation. Administrators must prioritize the deployment of the vendor-supplied update to version 1.11.00.022 to eliminate the underlying flaw. Until the update is applied, ensure that access to the DIAEnergie interface is restricted to authorized personnel only to minimize the risk of exploitation by malicious actors.
More Deltaww CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Alex Williams from Pellera Technologies, with VulnCheck (coordinator), per the CVE Program record.