DescriptionDelta Electronics DIAEnergie before 1.11.00.022 contains an authentication bypass vulnerability in its global Web API filters that allows remote unauthenticated attackers to bypass JWT and basic authentication checks by appending a whitelisted pattern to the query string of any protected endpoint. Attackers can exploit the unanchored whitelist matching against the full request URI, including attacker-controlled query parameters, to invoke privileged API actions such as creating administrator accounts and taking over the application.