Zalktis · Zalktis · CVE-2026-59109
**Name of the Vulnerable Software and Affected Versions**
Zalktis versions prior to 2026.1.586
Zalktis versions prior to 2026.2.592
**Description**
An issue exists where the application concatenates partner-controlled values directly into SQL statement text during the import of received electronic invoices (UBL/PEPPOL) or e-commerce exports. This occurs because the system fails to use parameterized queries or the internal escaping helper function `Dazadi.sql txt()`, allowing a sender to manipulate the query logic by breaking out of the string literal.
**Recommendations**
Update to version 2026.1.586 or later.
Update to version 2026.2.592 or later.