SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76156

CRITICAL · CVSS 9.4 EPSS 0.83%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated administrators of Datiphy Data Management Center versions 8.3.0 to 8.5.1 to perform OS command injection via the API endpoint, enabling them to execute arbitrary commands with root privileges. This critical flaw poses a significant risk of system compromise and data manipulation. Organizations using affected versions should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-76156
Severity
CRITICAL
CVSS
9.4
EPSS
0.83%

Original NVD Description

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.