CVE-2026-76156 PUBLISHED

Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command

Assigner: ZUSO ART
Reserved: 19.08.2026 Published: 21.08.2026 Updated: 21.08.2026

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor Datiphy Inc.
Product Data Management Center
Versions Default: unaffected
  • affected from v8.3.0 to v8.5.1 (incl.)

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE