Description
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Delta DIAEnergie v1.11.00.002 contains a SQL Injection flaw that can be exploited by supplying crafted input to vulnerable database queries. The injection allows an attacker to execute arbitrary SQL statements, which can be leveraged to achieve remote code execution. This enables full compromise of the affected system, compromising confidentiality, integrity, and availability of data and services.

Affected Systems

Affected systems are instances of Delta DIAEnergie version 1.11.00.002. No other product versions are known to be impacted according to the vendor's CNAs. The flaw resides in the database interaction layer of this specific release.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is classified as high severity. The EPSS score is not available, and the flaw is not listed in CISA's KEV catalog, indicating no confirmed active exploitation as of this analysis. Nonetheless, because the flaw is remote and allows code execution, the likely attack vector is over an exposed web interface or application layer and can be triggered without local privileges. An attacker with network access to the application could submit malicious input and gain remote execution capability.

Generated by OpenCVE AI on August 24, 2026 at 10:21 UTC.

Remediation

Vendor Solution

Users are advised to contact Delta technical support to obtain and update to DIAEnergie v1.11.00.022 or a later version.


OpenCVE Recommended Actions

  • Update Delta DIAEnergie to version 1.11.00.022 or later as advised by Delta support.
  • Enforce strict input validation and use parameterized queries to eliminate SQL Injection vectors.
  • Deploy a Web Application Firewall or similar filtering to block malicious SQL payloads.

Generated by OpenCVE AI on August 24, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
Title DIAEnergie - SQL Injection
First Time appeared Deltaww
Deltaww diaenergie
Weaknesses CWE-89
CPEs cpe:2.3:a:deltaww:diaenergie:*:*:*:*:*:*:*:*
Vendors & Products Deltaww
Deltaww diaenergie
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Deltaww Diaenergie
cve-icon MITRE

Status: PUBLISHED

Assigner: Deltaww

Published:

Updated: 2026-08-24T16:21:27.518Z

Reserved: 2026-08-24T08:32:54.874Z

Link: CVE-2026-78316

cve-icon Vulnrichment

Updated: 2026-08-24T16:21:21.247Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T10:16:40.667

Modified: 2026-09-01T21:11:35.983

Link: CVE-2026-78316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T11:30:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')