Junglewise Threat Intelligence

CVE-2026-78316: Delta DIAEnergie SQL injection in web application

CVE-2026-78316 · Severity: high · CVSS 8.8 · Published 2026-08-24

Technologies: Delta DIAEnergie. Vendors: Delta.

Executive brief

Delta DIAEnergie is an industrial energy management system used to monitor and control power distribution in facilities. A SQL injection vulnerability in version 1.11.00.002 allows an authenticated or remote attacker to execute arbitrary SQL queries, potentially leading to unauthorized database access, data manipulation, or remote code execution depending on database configuration and privileges.

Technical details

This vulnerability is a SQL injection flaw in Delta DIAEnergie v1.11.00.002 that permits attackers to inject malicious SQL commands into database queries. The vulnerable component fails to properly sanitize user-supplied input before incorporating it into SQL statements. Successful exploitation enables attackers to extract sensitive data from the database, modify or delete records, or in some database configurations, execute operating system commands. The attack vector and authentication requirements are not fully specified in the available advisory text; however, the high CVSS score (8.8) suggests network accessibility. Patches or updates may be available from Delta; refer to the vendor's security advisory (Delta-PCSA-2026-00015) for remediation guidance.

Affected products

  • Delta DIAEnergie 1.11.00.002

Timeline

  • 2026-08-24: disclosed

References

Related threats