Junglewise Threat Intelligence

CVE-2026-76156: Datiphy Data Management Center OS command injection in API

CVE-2026-76156 · Severity: info · Published 2026-08-21

Technologies: Datiphy Data Management Center. Vendors: Datiphy.

Executive brief

Datiphy Data Management Center is a data management platform used for enterprise data operations. An authenticated administrator can inject and execute arbitrary operating system commands with root privileges through the API endpoint, potentially compromising the entire system and all data it manages.

Technical details

This is an OS command injection vulnerability in the API endpoint of Datiphy Data Management Center (versions 8.3.0 through 8.5.1). The vulnerability allows an authenticated administrator to execute arbitrary operating system commands with root-level privileges. The attack requires valid administrator credentials and network access to the API endpoint. A successful exploit enables an attacker to gain complete control over the affected system, read/modify/delete data, and potentially pivot to other infrastructure. Patched versions beyond 8.5.1 are recommended.

Affected products

  • Datiphy Data Management Center 8.3.0 through 8.5.1

Timeline

  • 2026-08-21: disclosed

References

Related threats