PT-2026-71703 · Zalktis · Zalktis

·

CVE-2026-59109

·

Published

2026-08-13

·

Updated

2026-08-14

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zalktis versions prior to 2026.1.586 Zalktis versions prior to 2026.2.592
Description An issue exists where the application concatenates partner-controlled values directly into SQL statement text during the import of received electronic invoices (UBL/PEPPOL) or e-commerce exports. This occurs because the system fails to use parameterized queries or the internal escaping helper function Dazadi.sql txt(), allowing a sender to manipulate the query logic by breaking out of the string literal.
Recommendations Update to version 2026.1.586 or later. Update to version 2026.2.592 or later.

Exploit

Fix

SQL injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59109

Affected Products

Zalktis