DescriptionDelta Electronics DIAEnergie before 1.11.00.022 contains an authorization bypass vulnerability that allows authenticated attackers to access other users' privilege-group and function-level assignments by supplying an arbitrary user identifier in the request. Attackers can manipulate the user-controlled key parameter, provided as a plain integer or Base64-encoded value, to bypass per-module authorization filters and read any user's privilege and permission data.