{"id":"CVE-2026-59109","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-59109","summary":"SQL injection in the Zalktis accounting application via\ntrading-partner-controlled text fields in received electronic invoices. When\nimporting a received e-invoice (UBL/PEPPOL) or an…","details":"SQL injection in the Zalktis accounting application via\ntrading-partner-controlled text fields in received electronic invoices. When\nimporting a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis\nconcatenates partner-controlled values directly into SQL statement text using\nstring concatenation, with neither parameterised queries nor escaping. The\napplication's own escaping helper, Dazadi.sql_txt(),\nis not invoked on these code paths, so a party that sends an invoice can break\nout of the string literal and alter the query logic.\n\n\n\n\n\n\n\n\n\nThis issue affects Zalktis: before 2026.1.586 and before 2026.2.592.","published":"2026-08-13T17:17:29.207","modified":"2026-08-14T18:18:29.113","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://cvd.cert.lv/disclosed/vuln-all-631428755"},{"type":"WEB","url":"https://offseq.com/en/research/zalktis-cve-2026-59109"},{"type":"WEB","url":"https://offseq.com/en/research/zalktis-cve-2026-59109/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T18:18:29.113"}}