CVE-2026-76158 PUBLISHED

Datiphy Data Management Center - External Control of File Name or Path

Assigner: ZUSO ART
Reserved: 19.08.2026 Published: 21.08.2026 Updated: 21.08.2026

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor Datiphy Inc.
Product Data Management Center
Versions Default: unaffected
  • affected from v8.3.0 to v8.5.1 (incl.)

References

Problem Types

  • CWE-73 External control of file name or path CWE