Junglewise Threat Intelligence

CVE-2026-8654: Delphix Continuous Data connectors OS command injection

CVE-2026-8654 · Severity: info · CVSS 8.7 · Published 2026-05-15

Executive brief

Delphix Continuous Data connectors, which are used to manage and move data across environments, contain a security flaw that allows an authorized user to run unauthorized commands. An attacker with basic login credentials could take full control of the staging or target servers used for data processing. This could lead to the theft of sensitive data, disruption of data workflows, or further attacks on the corporate network.

Technical details

An OS command injection vulnerability (CWE-78) exists in Delphix Continuous Data connectors due to improper neutralization of special elements in user-supplied input. The flaw is reachable over the network and requires low-privileged authentication (PR:L). By providing specially crafted input to the connector, an attacker can execute arbitrary shell commands with the privileges of the connector process on the underlying staging or target operating system. This results in a complete loss of confidentiality, integrity, and availability for the affected host. The vulnerability was disclosed by Perforce with a CVSS 4.0 score of 8.7.

Affected products

  • Delphix Continuous Data connectors

Timeline

  • 2026-05-15: disclosed: Initial disclosure by Perforce and NVD publication.

References