Description
Authorization Bypass Through User-Controlled Key in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.
Published: 2026-09-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Update
AI Analysis

Impact

The vulnerability lets an attacker supply a user‑controlled key and bypass the application’s authorization checks. If exploited, the attacker can gain unauthorized access to protected functions or data. The flaw is a direct example of CWE‑639 (Authorization Bypass Through User‑Controlled Key).

Affected Systems

Affected are all installations of Deltaww’s DIAEnergie product running a version prior to 1.11.00.022. No other product or version is listed as impacted in the advisory.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, suggesting no publicly known exploitation activity. The vulnerability is not included in the CISA KEV catalog. Attackers would need to supply the specific key value, so the required attack vector is inferred to be either local or remote access to the application, provided the user‑controlled key mechanism is exposed. Without a public exploit, the likelihood of exploitation remains low but non‑zero.

Generated by OpenCVE AI on September 24, 2026 at 10:24 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Apply the official DIAEnergie update (v1.11.00.022 or later) provided by Delta technical support.
  • If an immediate update is not possible, disable the user‑controlled key feature or enforce a hard‑coded key to prevent bypass.
  • Continuously monitor authentication and usage logs for anomalous key activity and isolate any endpoints that exhibit compromised behavior.

Generated by OpenCVE AI on September 24, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Title Authorization Bypass Through User-Controlled Key in DIAEnergie
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-639
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-09-24T12:34:01.643Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T09:17:08.323

Modified: 2026-09-24T19:39:45.600

Link: CVE-2026-78310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T10:30:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key