External Control of File Path in Datiphy Data Management Center
CVE-2026-76158
9.3CRITICAL
What is CVE-2026-76158?
The Datiphy Data Management Center presents a vulnerability where an external control of file names or paths occurs in its upload API endpoint. This flaw, present from version 8.3.0 to 8.5.1, enables remote attackers to exploit the system by manipulating file upload paths. Consequently, attackers may write files to arbitrary locations outside of the intended upload directory, posing serious security risks to the integrity and confidentiality of sensitive data.
Affected Version(s)
Data Management Center v8.3.0
