Home

Description

Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.

PUBLISHED Reserved 2026-05-15 | Published 2026-05-15 | Updated 2026-05-15 | Assigner Perforce




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Product status

Default status
unaffected

Any version before 2025.2
affected

Default status
unaffected

Any version before 2025.2.1
affected

Default status
unaffected

Any version before 2025.1.0
affected

Default status
unaffected

Any version before 2025.1.0
affected

Default status
unaffected

Any version before 2025.2.0
affected

Default status
unaffected

Any version before 2026.2.0
affected

Default status
unaffected

Any version before 2025.2.0
affected

Default status
unaffected

Any version before 1.3.2
affected

Default status
unaffected

Any version before 2025.1.0
affected

Default status
unaffected

Any version before 2025.1.1
affected

Default status
unaffected

Any version before 2025.1.0
affected

Default status
unaffected

Any version before 4.2.1
affected

References

portal.perforce.com/...in-delphix-continuous-data-connectors vendor-advisory

cve.org (CVE-2026-8654)

nvd.nist.gov (CVE-2026-8654)

Download JSON