Description
Path Traversal in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.
Published: 2026-09-24
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows an attacker to reference filesystem paths outside the intended directory boundaries. This could enable reading of arbitrary files, potentially exposing sensitive information, and if writable locations are reachable, could lead to arbitrary file write or code execution in the context of the application.

Affected Systems

The affected product is Delta's DIAEnergie, with vulnerability present in all releases prior to version 1.11.00.022.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the high score and the nature of the flaw suggest that exploitation is likely feasible over a remote network connection, such as through the web interface or API. An attacker with network access could craft requests containing malicious path sequences to read arbitrary files or, if write access is possible, modify files to achieve further compromise.

Generated by OpenCVE AI on September 24, 2026 at 10:23 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Upgrade to DIAEnergie v1.11.00.022 or later as advised by Delta technical support.
  • Configure the application to reject directory traversal patterns such as "../" and enforce a strict root directory for file accesses.
  • Deploy web application firewall rules to detect and block path traversal attempts until an application update can be applied.

Generated by OpenCVE AI on September 24, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Title Path Traversal in DIAEnergie
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-22
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-09-24T12:33:39.775Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-24T09:17:08.553

Modified: 2026-09-24T19:39:45.600

Link: CVE-2026-78312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T10:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')