Authentication Bypass in Datiphy Data Management Center Upload API
CVE-2026-76157

8.8HIGH

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-76157?

A vulnerability in the upload API endpoint of Datiphy Data Management Center versions 8.3.0 to 8.5.1 allows unauthenticated remote attackers to upload arbitrary files to the server's designated directory. This security flaw poses a significant risk, as it could lead to the execution of malicious files on the server, potentially compromising sensitive data and system integrity.

Affected Version(s)

Data Management Center v8.3.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.