SQL Injection Vulnerability in Zalktis Accounting Application
CVE-2026-59109
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 13 August 2026
What is CVE-2026-59109?
The Zalktis accounting application is vulnerable to SQL injection through improperly sanitized input within trading-partner-controlled fields in received electronic invoices. When importing electronic invoices (UBL/PEPPOL) or e-commerce data, Zalktis incorporates these values directly into SQL statements without employing parameterized queries or proper escaping techniques. This oversight allows malicious actors to manipulate the SQL query logic by breaking out of the string literal, potentially leading to unauthorized data access or manipulation.
Affected Version(s)
Zalktis Windows 0 < 2026.1.586
Zalktis Windows 0 < 2026.2.592
