{"id":"CVE-2026-78308","published":"2026-09-24T09:17:08.043","lastModified":"2026-09-24T19:39:45.600","description":"Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass.\n\nThis issue affects DIAEnergie: before 1.11.00.022.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://filecenter.deltaww.com/news/download/doc/Delta-PCSA-2026-00014_DIAEnergie%20Multiple%20Vulberabilities%20(CVE-2026-78308%20~%2078313).pdf","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an Improper Authentication vulnerability in DIAEnergie that allows Authentication Bypass, enabling unauthorized access to the system. This matters because it can lead to significant data compromise and operational disruption.","exploitability":"Exploitation is relatively straightforward with no preconditions required, as it allows bypassing authentication mechanisms entirely.","blast_radius":"If exploited, this could result in unauthorized access to sensitive data and control over critical system functions, impacting the entire organization's operations and security posture.","remediation":"Upgrade to DIAEnergie version 1.11.00.022 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","critical","vulnerability","upgrade","defensive"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:52:08.308Z"}}