CVE-2026-78311

8.8

Deltaww · DIAEnergie

A SQL injection vulnerability in Deltaww DIAEnergie allows authenticated attackers to execute arbitrary SQL commands.

Executive summary

A high-severity SQL injection vulnerability in Deltaww DIAEnergie poses a significant risk of unauthorized data access and system compromise for authenticated users.

Vulnerability

The application is susceptible to SQL injection (CWE-89) due to improper neutralization of special elements used in an SQL command. The vulnerability is exploitable by an authenticated user via the network.

Business impact

Successful exploitation allows an attacker to manipulate backend database queries, potentially leading to unauthorized data exfiltration, modification, or complete database takeover. Given the CVSS score of 8.8, this vulnerability carries a high impact on data confidentiality, integrity, and availability, which could result in severe operational disruption and the compromise of sensitive industrial energy management data.

Remediation

Immediate Action: Update DIAEnergie to version 1.11.00.022 or later by contacting Delta technical support.

Proactive Monitoring: Review database audit logs for anomalous query patterns, unexpected syntax errors, or unauthorized access attempts originating from standard user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with SQL injection protection rules enabled to filter malicious input strings directed at the application.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Deltaww DIAEnergie users should prioritize the transition to version 1.11.00.022 immediately. Given the nature of SQL injection flaws, applying the vendor-supplied patch is the only definitive way to remediate the underlying code vulnerability and prevent potential unauthorized database access.

More Deltaww CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Alex Williams from Pellera Technologies, with VulnCheck (coordinator), per the CVE Program record.