CVE-2026-78317

8.8

Delta · DIAEnergie

Delta DIAEnergie versions up to 1.11.00.002 contain an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands.

Executive summary

A high-severity SQL injection vulnerability in Delta DIAEnergie allows authenticated attackers to manipulate backend database queries, potentially leading to unauthorized data access or modification.

Vulnerability

This vulnerability is an SQL injection flaw (CWE-89) arising from the improper neutralization of special elements used in SQL commands. The attack requires low privileges (authenticated) to successfully exploit the application.

Business impact

The ability to inject arbitrary SQL queries poses a severe risk to data integrity and confidentiality. An attacker could bypass application security controls to extract sensitive information, modify database records, or potentially disrupt service availability. With a CVSS score of 8.8, this vulnerability is classified as High, reflecting the significant potential for total compromise of the database layer.

Remediation

Immediate Action: Users must contact Delta technical support to obtain and upgrade to DIAEnergie version 1.11.00.022 or a later version.

Proactive Monitoring: Security teams should review database access logs for unusual queries, specifically those containing suspicious SQL syntax or patterns indicative of injection attempts.

Compensating Controls: Implement a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection payloads before they reach the application.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the High severity of this vulnerability and the risk of unauthorized database manipulation, administrators should treat this update with urgency. Contact the vendor immediately to secure the installation and audit existing database access logs for any signs of prior exploitation.

More Delta CVEs