Description
Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass.

This issue affects DIAEnergie: before 1.11.00.022.
Published: 2026-09-24
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch
AI Analysis

Impact

Improper authentication in DIAEnergie allows an attacker to bypass the login process, potentially granting unauthorized access to the application and its data. The flaw is identified as CWE-287. Users operating versions prior to 1.11.00.022 are susceptible, and exploitation could provide full control over the interface and any protected resources.

Affected Systems

The vulnerability affects the Deltaww product DIAEnergie. Any installation of DIAEnergie before version 1.11.00.022 is vulnerable, as indicated by the vendor’s CPE designation for deltaww:diaenergie.

Risk and Exploitability

With a CVSS score of 9.8, this issue is critical. While the EPSS score is not available, the remote nature of authentication bypass suggests a high likelihood of exploitation, especially if the service is exposed to the internet or an internal network. The vulnerability is not listed in CISA KEV, but that does not mitigate the severity. The likely attack vector is a remote attacker accessing the DIAEnergie interface over the network and using the bypass to gain privileged access.

Generated by OpenCVE AI on September 24, 2026 at 09:21 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Update DIAEnergie to version 1.11.00.022 or a later release as advised by Delta technical support.
  • Limit network exposure of the DIAEnergie interface by implementing firewall rules or VLAN segmentation until the update can be applied.
  • Confirm that authentication is enforced and that no default or hard‑coded credentials remain in configuration files or environment variables.

Generated by OpenCVE AI on September 24, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
Title Authentication Bypass in DIAEnergie
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-287
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-09-24T12:36:20.452Z

Reserved: 2026-08-24T08:32:54.873Z

Link: CVE-2026-78308

cve-icon Vulnrichment

Updated: 2026-09-24T12:36:17.420Z

cve-icon NVD

Status : Received

Published: 2026-09-24T09:17:08.043

Modified: 2026-09-24T13:17:10.747

Link: CVE-2026-78308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T09:30:20Z

Weaknesses