---
id: CVE-2026-78309
title: |-
  SQL Injection vulnerability in DIAEnergie.

  This issue affects DIAEnergie: before 1.11.00.022.
summary: |-
  SQL Injection vulnerability in DIAEnergie.

  This issue affects DIAEnergie: before 1.11.00.022.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: Deltaww
product: DIAEnergie
affected:
  - DIAEnergie < 1.11.00.022
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T19:39:45.600'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78309'
references:
  - url: >-
      https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf
    label: 759f5e80-c8e1-4224-bead-956d7b33c98b
tags:
  - nvd
  - cve.org
epss: 0.00239
epssPercentile: 0.13289
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T12:35:52.560561Z'
ingestedAt: '2026-09-24T09:40:50.742Z'
---

## Overview

SQL Injection vulnerability in DIAEnergie.

This issue affects DIAEnergie: before 1.11.00.022.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
