Description
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a SQL injection flaw in Delta DIAEnergie version 1.11.00.002, as described in the vendor advisory. An attacker who can inject malicious SQL statements can cause the application to execute arbitrary code on the underlying operating system. The excerpt in the CVE description explicitly states that this leads to remote code execution. The information does not indicate whether authentication or privileged access is required to exploit the flaw, so the exact attack vector or prerequisites remain unspecified.

Affected Systems

Delta DIAEnergie v1.11.00.002 is the only variant identified as vulnerable. Delta Technical Support recommends updating to version 1.11.00.022 or later. Users should verify the installed version against the vendor list of affected releases.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is considered high severity. EPSS data is not available, so the current likelihood of exploitation cannot be quantified. The issue is not listed in CISA’s KEV catalog, but the confirmed remote code execution impact warrants urgent remediation, especially in environments where the application accepts input from untrusted sources.

Generated by OpenCVE AI on August 24, 2026 at 10:51 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Update Delta DIAEnergie to v1.11.00.022 or a later release provided by Delta Technical Support
  • Restrict database access to trusted network segments or services only, limiting exposure to attacker input
  • Ensure all user-supplied data is validated and used only in properly parameterized queries to eliminate injection opportunities

Generated by OpenCVE AI on August 24, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
Title DIAEnergie - SQL Injection
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-89
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-08-24T16:27:52.884Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78314

cve-icon Vulnrichment

Updated: 2026-08-24T16:27:47.803Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T10:16:40.370

Modified: 2026-09-01T21:11:35.983

Link: CVE-2026-78314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T11:00:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')