← back
CVE-2026-76156criticalCWE-78

Datiphy Data Management Center - Improper Neutralization of Special Elements used in an OS Command

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.4epss 0.8%
exploitation probability
0.8%top 44% of all CVEs
observed exploitation
nono source reports it
OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H