Skip to content
delta-electronicsCVE-2026-78314

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

High8.8CVE-2026-78314 · Published Aug 24, 2026 · updated Sep 1, 2026

Source advisory

Affected versions

PackageAffectedFixed in
DIAEnergie
Vendor
<= 1.11.00.002No fix yet
Details and references

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
no source yet
Weakness
CWE-89

More delta-electronics advisories

All
DateAdvisory
Aug 24SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78315High8.8no fix yet
Aug 24SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78316High8.8no fix yet
Aug 24SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78317High8.8no fix yet
Sep 24Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78308Critical9.8fixed in DIAEnergie 1.11.00.022
Sep 24SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78309High8.8fixed in DIAEnergie 1.11.00.022
Sep 24Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.
CVE-2026-78310Medium4.3fixed in DIAEnergie 1.11.00.022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.