Description
Improper Access Control in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.
Published: 2026-09-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Patch Immediately
AI Analysis

Impact

Improper Access Control in DIAEnergie allows an attacker to gain unauthorized access to system functionality or sensitive information that should be protected by authentication or authorization controls. The vulnerability could enable users to perform operations or view data beyond their intended privileges, potentially compromising confidentiality or integrity of the application’s data.

Affected Systems

Deltaww’s DIAEnergie software, versions prior to 1.11.00.022, is affected. The vulnerability impacts any deployment of this product that has not been upgraded to the specified version or later.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the vulnerability arises from improper access control and would likely be exploitable by an attacker who can interact with the application—either locally or remotely if that interface is exposed. No specific exploit code or configuration is mentioned, so the attack would require reaching the affected component and manipulating authentication or authorization controls.

Generated by OpenCVE AI on September 24, 2026 at 10:50 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Contact Delta technical support to obtain and upgrade to DIAEnergie v1.11.00.022 or a later version.
  • Reconfigure authorization controls to enforce least privilege, ensuring that users only have permissions required for their roles.
  • Enable and review audit logging of access events to detect potential privilege escalation or unauthorized activity.

Generated by OpenCVE AI on September 24, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
Title Improper Access Control in DIAEnergie
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-284
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-09-24T12:49:37.636Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78313

cve-icon Vulnrichment

Updated: 2026-09-24T12:47:01.827Z

cve-icon NVD

Status : Received

Published: 2026-09-24T09:17:08.673

Modified: 2026-09-24T13:17:11.277

Link: CVE-2026-78313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T11:00:14Z

Weaknesses