Description
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

SQL injection in Delta DIAEnergie v1.11.00.002 allows an attacker to inject arbitrary SQL statements. By exploiting unsanitized input fields the attacker can manipulate database queries and ultimately execute code on the host system, leading to full compromise of confidentiality, integrity, and availability. The weakness is a classic input validation flaw represented by CWE‑89.

Affected Systems

Affected vendor is Delta, product DIAEnergie. The vulnerability applies to version v1.11.00.002 and earlier releases, with the fix available in v1.11.00.022 or later. No other affected versions are listed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity level, and the EPSS score is not currently available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, but the possibility of remote exploitation via a web interface makes it a high‑risk threat. An attacker could construct a malicious request containing injected SQL syntax, causing the application to run unintended database commands that bypass authentication or trigger system calls for code execution.

Generated by OpenCVE AI on August 24, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch by upgrading to DIAEnergie version 1.11.00.022 or later.
  • If an upgrade cannot be applied immediately, contact Delta technical support to obtain an updated build.
  • Review application code to enforce parameterized queries and restrict database user privileges to the minimum required for operation.

Generated by OpenCVE AI on August 24, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
Title DIAEnergie - SQL Injection
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-89
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-08-24T16:22:27.657Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78315

cve-icon Vulnrichment

Updated: 2026-08-24T16:22:12.534Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T10:16:40.510

Modified: 2026-09-01T21:11:35.983

Link: CVE-2026-78315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T11:00:09Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')