Executive brief
Datiphy Data Management Center is a data management platform used for enterprise data operations. An authenticated administrator can inject and execute arbitrary operating system commands with root privileges through the API endpoint, potentially compromising the entire system and all data it manages.
Technical details
This is an OS command injection vulnerability in the API endpoint of Datiphy Data Management Center (versions 8.3.0 through 8.5.1). The vulnerability allows an authenticated administrator to execute arbitrary operating system commands with root-level privileges. The attack requires valid administrator credentials and network access to the API endpoint. A successful exploit enables an attacker to gain complete control over the affected system, read/modify/delete data, and potentially pivot to other infrastructure. Patched versions beyond 8.5.1 are recommended.
Affected products
- Datiphy Data Management Center 8.3.0 through 8.5.1
Timeline
- 2026-08-21: disclosed