Summary
CVE-2026-76155 is a critical vulnerability in Datiphy Data Management Center caused by the use of default, unchanged administrator credentials (CWE-1392). A remote, unauthenticated attacker can log in to the management platform using the default administrator account and gain full administrative control. The flaw affects Datiphy Data Management Center versions v8.3.0 through v8.5.1 and carries a CVSS score of 9.3 (Critical).
Technical details
- Root cause: The Datiphy Data Management Center ships with (or allows continued use of) a default administrator account and password that is not required to be changed during setup.
- Trigger conditions: An instance of the management platform that is reachable over the network and still has the default administrator credentials active/unrotated.
- Attack vector: Network — an attacker simply authenticates to the exposed management interface using the known default credentials; no user interaction or prior access is required.
- Impact: Successful exploitation grants the attacker full administrative access to the Data Management Center, resulting in high impact to confidentiality, integrity, and availability of the platform and any data or engines it manages.
Affected software
- Datiphy Data Management Center v8.3.0
- Datiphy Data Management Center v8.4.x
- Datiphy Data Management Center v8.5.0
- Datiphy Data Management Center v8.5.1
(Versions outside the v8.3.0–v8.5.1 range are not identified as affected in the CVE record.)
Severity
- CVSS v4.0 Base Score: 9.3 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - Attack Vector: Network | Attack Complexity: Low | Privileges Required: None | User Interaction: None | Impact: High confidentiality, integrity, and availability impact
Note: The published CVE record scores this vulnerability using the CVSS v4.0 standard; a CVSS v3.1 vector has not been published by the assigning CNA at the time of this writing.
Mitigation and recommended actions
- Immediate: Change the default administrator password on all Datiphy Data Management Center deployments (v8.3.0–v8.5.1) immediately, and confirm with Datiphy whether a patched release beyond v8.5.1 is available for your deployment.
- If no patch is available:
- Rotate all default/administrative credentials to strong, unique passwords.
- Restrict network access to the Data Management Center management interface to trusted management networks only (e.g., via firewall rules, VPN, or network segmentation) — do not expose it directly to the internet.
- Enable logging/monitoring of administrative logins to detect use of default or suspicious credentials.
- Review existing accounts for any unauthorized administrative access that may have already occurred.

