PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-59109 Zalktis Programmas (SIA "Zalktis Programmas") CVE debrief

The CVE-2026-59109 record describes a SQL injection vulnerability in the Zalktis accounting application. This vulnerability occurs when trading-partner-controlled text fields in received electronic invoices are improperly handled, allowing an attacker to inject malicious SQL code and alter query logic. The vulnerability affects Zalktis versions before 2026.1.586 and before 2026.2.592. Organizations using Zalktis for accounting purposes, especially those exposed to untrusted trading partners, should be aware of this vulnerability and take necessary actions to mitigate the risk. The CVE record was published on 2026-08-13T17:17:29.207Z and has not been modified since then.

Vendor
Zalktis Programmas (SIA "Zalktis Programmas")
Product
Zalktis
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-13
Original CVE updated
2026-09-01
Advisory published
2026-08-13
Advisory updated
2026-09-01

Who should care

Organizations using Zalktis for accounting purposes, especially those exposed to untrusted trading partners, should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes inventorying and assessing exposure of Zalktis instances to untrusted trading partners, applying patches or updates to Zalktis versions before 2026.1.586 and before 2026.2.592, implementing compensating controls such as Web Application Firewalls (WAFs) to detect and prevent SQL injection attacks, monitoring for suspicious activity and exception tracking, and verifying vendor remediation and performing retesting. Security teams and vulnerability management teams should prioritize patching to prevent potential SQL injection attacks. IT operators and administrators should review and implement the recommended actions to ensure the security of their systems. Additionally, defenders should verify the affected scope, severity, and vendor guidance to ensure proper mitigation of the vulnerability. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This requires coordination between security teams, IT operators, and administrators to ensure effective mitigation and remediation of the vulnerability. The vulnerability's impact on the organization depends on the effectiveness of its vulnerability management and security practices. Therefore, it is crucial for organizations to assess their exposure and implement necessary controls to prevent exploitation. The CVE description and source references provide further details on the vulnerability and recommended actions. By taking these steps, organizations can minimize the risk associated with this SQL injection vulnerability in the Zalktis accounting application. The vulnerability's severity and potential impact emphasize the need for prompt attention and remediation. By prioritizing patching and implementing compensating controls, organizations can protect their systems from potential SQL injection attacks. The CVE record and source references provide essential information for defenders to understand and mitigate the vulnerability effectively. The affected Zal

Technical summary

The Zalktis accounting application is vulnerable to SQL injection attacks due to improper handling of trading-partner-controlled text fields in received electronic invoices. This allows an attacker to inject malicious SQL code and alter the query logic. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.

Defensive priority

Organizations using Zalktis versions before 2026.1.586 and before 2026.2.592 should prioritize patching to prevent potential SQL injection attacks.

Recommended defensive actions

  • Inventory and assess exposure of Zalktis instances to untrusted trading partners
  • Apply patches or updates to Zalktis versions before 2026.1.586 and before 2026.2.592
  • Implement compensating controls such as Web Application Firewalls (WAFs) to detect and prevent SQL injection attacks
  • Monitor for suspicious activity and exception tracking
  • Verify vendor remediation and perform retesting

Evidence notes

The CVE description indicates a SQL injection vulnerability in Zalktis accounting application due to concatenation of trading-partner-controlled text fields in received electronic invoices without parameterized queries or escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-59109 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-59109

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-59109 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-59109

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cvd.cert.lv/disclosed/vuln-all-631428755

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

  • Source reference

    Unverified legacy reference

    URL: https://offseq.com/en/research/zalktis-cve-2026-59109

    a6d3dc9e-0591-4a13-bce7-0f5b31ff6158

  • Source reference

    Unverified legacy reference

    URL: https://offseq.com/en/research/zalktis-cve-2026-59109/

    134c704f-9b21-4f2e-91b3-4a467353bcc0

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.