Junglewise Threat Intelligence

CVE-2026-76155: Datiphy Data Management Center default credentials authentication bypass

CVE-2026-76155 · Severity: info · Published 2026-08-21

Technologies: Datiphy Data Management Center. Vendors: Datiphy.

Executive brief

Datiphy Data Management Center is a platform used to manage and control data operations across enterprise environments. Versions 8.3.0 through 8.5.1 ship with unchangeable default administrator credentials, allowing an unauthenticated remote attacker to log in and gain full administrative access to the management platform without any legitimate authorization.

Technical details

This vulnerability is a credential management weakness (CWE-798: Use of Hard-Coded Credentials) affecting Datiphy Data Management Center versions 8.3.0 through 8.5.1. The product contains default administrator credentials that cannot be changed or are difficult to identify during deployment, enabling remote network-based authentication bypass. An attacker with network access to the management interface can authenticate using these default credentials to gain unrestricted administrative privileges over the platform, including the ability to modify configurations, access sensitive data, create additional user accounts, or disrupt operations. No patch information is currently available in the advisory.

Affected products

  • Datiphy Data Management Center 8.3.0 through 8.5.1

Timeline

  • 2026-08-21: disclosed

References

Related threats