External Control of File Path in Datiphy Data Management Center
CVE-2026-76158

9.3CRITICAL

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-76158?

The Datiphy Data Management Center presents a vulnerability where an external control of file names or paths occurs in its upload API endpoint. This flaw, present from version 8.3.0 to 8.5.1, enables remote attackers to exploit the system by manipulating file upload paths. Consequently, attackers may write files to arbitrary locations outside of the intended upload directory, posing serious security risks to the integrity and confidentiality of sensitive data.

Affected Version(s)

Data Management Center v8.3.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.