trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.
No analysis available yet.
Vendor Solution
The vendor addressed the issue by parameterising the affected queries. Upgrade to 2026.1.586 (legacy branch) or 2026.2.592 (current branch) or later.
Vendor Workaround
Until a fixed build is deployed: do not import e-invoices or e-commerce exports received from untrusted senders, and keep restorable backups of the accounting database taken before any import.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592. | |
| Title | Zalktis: SQL injection via partner-controlled fields in imported e-invoices | |
| Weaknesses | CWE-20 CWE-89 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-08-13T16:40:01.751Z
Reserved: 2026-07-02T15:47:36.965Z
Link: CVE-2026-59109
No data.
Status : Received
Published: 2026-08-13T17:17:29.207
Modified: 2026-08-13T17:17:29.207
Link: CVE-2026-59109
No data.
OpenCVE Enrichment
No data.