CVE-2026-59109

HIGH CVSS 4.0: 8.7 EPSS 0.31%
Updated Aug 14, 2026
SQL
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions before 2026.1.586
Type CWE-89 (SQL Injection), CWE-20 (Improper Input Validation)
Vendor SQL
Public PoC No

SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic.

This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0