Answer in brief
CVE-2026-59109 records a High severity (CVSS 8.8) vulnerability in Zalktis: SQL injection via partner-controlled fields in imported e-invoices. The current sources do not mark it as known exploited. The current feed maps Zalktis Programmas (SIA "Zalktis Programmas")/Zalktis (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Zalktis Programmas (SIA "Zalktis Programmas")/Zalktis (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Zalktis Programmas (SIA "Zalktis Programmas")/Zalktisgeneric | >=0 <2026.1.586 || >=0 <2026.2.592 | 2026.1.586, 2026.2.592 |
Published upstream
Aug 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 1, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement text using string concatenation, with neither parameterised queries nor escaping. The application's own escaping helper, Dazadi.sql_txt(), is not invoked on these code paths, so a party that sends an invoice can break out of the string literal and alter the query logic. This issue affects Zalktis: before 2026.1.586 and before 2026.2.592.
Quoted source text, attributed separately from HOL analysis.