{"apiVersion":"1.0","identifier":"CVE-2026-59109","description":"SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application-s own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.","publishedAt":"2026-08-13T17:17:29","lastModifiedAt":"2026-08-14T18:18:29","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59109","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","epssProbability":0.00312,"riskScore":0.9,"affectedProduct":"Zalktis","affectedVersions":"<2026.1.586, <2026.2.592","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-59109","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-59109","en":"https://www.redsauce.net/en/cves/CVE-2026-59109","fr":"https://www.redsauce.net/fr/cves/CVE-2026-59109","pt":"https://www.redsauce.net/pt/cves/CVE-2026-59109","de":"https://www.redsauce.net/de/cves/CVE-2026-59109","sk":"https://www.redsauce.net/sk/cves/CVE-2026-59109","el":"https://www.redsauce.net/el/cves/CVE-2026-59109"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-59109"}}