CVE-2026-8654: Delphix Continuous Data Cassandra Connector
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
Affected products
- Delphix Continuous Data Cassandra Connector: before 2025.1.0 (fixed in 2025.1.0)
- Delphix Continuous Data Cockroachdb Connector: before 2025.2.0 (fixed in 2025.2.0)
- Delphix Continuous Data Couchbase Connector: before 1.3.2 (fixed in 1.3.2)
- Delphix Continuous Data IBM DB2 Connector: before 2025.2 (fixed in 2025.2)
- Delphix Continuous Data Mangodb Connector: before 2025.2.1 (fixed in 2025.2.1)
- Delphix Continuous Data Mssql On Linux Connector: before 2025.1.0 (fixed in 2025.1.0)
- Delphix Continuous Data MySQL Connector: before 2025.1.0 (fixed in 2025.1.0)
- Delphix Continuous Data Oracle Backup Ingestion Connector: before 4.2.1 (fixed in 4.2.1)
- Delphix Continuous Data Oracle Ebs Connector: before 2025.2.0 (fixed in 2025.2.0)
- Delphix Continuous Data PostgreSQL Connector: before 2025.1.0 (fixed in 2025.1.0)
- Delphix Continuous Data SAP Hana Connector: before 2026.2.0 (fixed in 2026.2.0)
- Delphix Continuous Data Yugabytedb Connector: before 2025.1.1 (fixed in 2025.1.1)
Published 2026-05-15. Last modified 2026-06-17.