Skip to content
delta-electronicsCVE-2026-78310

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Medium4.3CVE-2026-78310 · Published Sep 24, 2026

Source advisory

Affected versions

PackageAffectedFixed in
DIAEnergie
Vendor
< 1.11.00.0221.11.00.022
Details and references

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
no source yet
Weakness
CWE-639

More delta-electronics advisories

All
DateAdvisory
Sep 24Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78308Critical9.8fixed in DIAEnergie 1.11.00.022
Sep 24SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309High8.8fixed in DIAEnergie 1.11.00.022
Sep 24SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78311High8.8fixed in DIAEnergie 1.11.00.022
Sep 24Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78312Critical9.1fixed in DIAEnergie 1.11.00.022
Sep 24Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78313Medium6.5fixed in DIAEnergie 1.11.00.022
Aug 24SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78314High8.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.