Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Zalktis: SQL injection via partner-controlled fields in imported e-invoices
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N P H H H 8.7 .0031 24.0 —
AFFECTED
Product Versions Fixed
Zalktis unspecified —
TIMELINE
Jul 2 Reserved by ENISA
Aug 13 Published (CNA: ENISA)
Aug 14 EXPLOIT PUBLISHED — CVE-2026-59109 (Zalktis Programmas (SIA "Zalktis Programmas") Zalktis). Public exploit reference added.
Description
SQL injection in the Zalktis accounting application via
trading-partner-controlled text fields in received electronic invoices. When
importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis
concatenates partner-controlled values directly into SQL statement text using
string concatenation, with neither parameterised queries nor escaping. The
application's own escaping helper, Dazadi.sql_txt(),
is not invoked on these code paths, so a party that sends an invoice can break
out of the string literal and alter the query logic.
This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 2, 2026 | Reserved | Reserved by ENISA |
| August 13, 2026 | Published | Published (CNA: ENISA) |
| August 14, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-59109 (Zalktis Programmas (SIA "Zalktis Programmas") Zalktis). Public exploit reference added. |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-59109 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.