Executive brief
Delta DIAEnergie is an energy management and monitoring platform used by organizations to track and optimize power consumption. A SQL injection vulnerability in version 1.11.00.002 allows an attacker to execute arbitrary SQL queries and potentially achieve remote code execution on the affected system, compromising the integrity and availability of energy monitoring operations.
Technical details
The vulnerability is a SQL injection flaw in Delta DIAEnergie v1.11.00.002 that permits unauthenticated or low-privilege attackers to inject malicious SQL commands through unvalidated user input. By exploiting this SQL injection, an attacker can potentially execute arbitrary code on the underlying database or application server, depending on the database configuration and application logic. The vulnerability is network-accessible and requires no prior authentication. Successful exploitation leads to complete system compromise with potential for data theft, data modification, or denial of service. Patched versions are available from Delta.
Affected products
- Delta DIAEnergie 1.11.00.002
Timeline
- 2026-08-24: disclosed