Executive brief
Delta DIAEnergie is energy management software used to monitor and control industrial power systems. A SQL injection vulnerability in version 1.11.00.002 allows an attacker to execute arbitrary code on affected systems, potentially leading to unauthorized control of critical infrastructure, data theft, or system compromise.
Technical details
The vulnerability is a SQL injection flaw in Delta DIAEnergie v1.11.00.002 that enables remote code execution. The SQL injection can be exploited to execute arbitrary SQL commands and, depending on the database configuration and privileges, achieve code execution on the underlying system. Attack vectors and specific preconditions (such as network accessibility or authentication requirements) are not detailed in the provided summary. The vulnerability has been assigned CVE-2026-78314 with a CVSS score of 8.8, indicating high severity. Delta has issued an advisory (PCSA-2026-00015) and patches are expected to be available.
Affected products
- Delta DIAEnergie 1.11.00.002
Timeline
- 2026-08-24: disclosed