Back to all
2026-08-21

Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command

ZUSOART ID
ZA-2026-05
CVE ID
CVE-2026-76156
Vulnerability Type
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 4.0 Base
9.4
Description

OS  command injection in the api endpoint of Datiphy Data Management Center from  v8.3.0 through v8.5.1 allows an authenticated administrator to execute  arbitrary operating system commands as root.

‍

Vendor
Datiphy Inc.
Product
Category
Version affected
Data Management Center
from v8.3.0 through v8.5.1
Mitigations

Contact  Datiphy for version updates.

‍

Release date
2026-08-21
Credit

Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART

‍