Junglewise Threat Intelligence

CVE-2026-78314: Delta DIAEnergie SQL injection allowing remote code execution

CVE-2026-78314 · Severity: high · CVSS 8.8 · Published 2026-08-24

Technologies: Delta DIAEnergie. Vendors: Delta.

Executive brief

Delta DIAEnergie is energy management software used to monitor and control industrial power systems. A SQL injection vulnerability in version 1.11.00.002 allows an attacker to execute arbitrary code on affected systems, potentially leading to unauthorized control of critical infrastructure, data theft, or system compromise.

Technical details

The vulnerability is a SQL injection flaw in Delta DIAEnergie v1.11.00.002 that enables remote code execution. The SQL injection can be exploited to execute arbitrary SQL commands and, depending on the database configuration and privileges, achieve code execution on the underlying system. Attack vectors and specific preconditions (such as network accessibility or authentication requirements) are not detailed in the provided summary. The vulnerability has been assigned CVE-2026-78314 with a CVSS score of 8.8, indicating high severity. Delta has issued an advisory (PCSA-2026-00015) and patches are expected to be available.

Affected products

  • Delta DIAEnergie 1.11.00.002

Timeline

  • 2026-08-24: disclosed

References

Related threats