CVE-2026-76156: Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command
Published Aug 21, 2026
·Updated
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
Affected Software
1 affected component
Datiphy Data Management Center>=8.3.0<=8.5.1
Event History
Aug 21, 2026
CVE Published
via MITRE·01:44 AM
Data Sourced
via MITRE·01:44 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires an authenticated administrator account on an affected Datiphy Data Management Center instance.
2
What level of access could successful exploitation provide?
An attacker who exploits the vulnerable API endpoint can execute arbitrary operating system commands as root.
3
Which releases are affected?
Datiphy Data Management Center versions from 8.3.0 through 8.5.1 are affected.