2026-08-21

Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command

ZUSOART ID ZA-2026-05
CVE ID CVE-2026-76156
Vulnerability Type CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 4.0 Base CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H (9.4)
Description OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
Vendor Datiphy Inc.
Product
Category Version affected
Data Management Center from v8.3.0 through v8.5.1
Product Support Contact Datiphy for version updates.
Release date 2026/08/21
Credit Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART
top