CVE-2026-76158: Datiphy Data Management Center - External Control of File Name or Path
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker can exploit the vulnerable upload API endpoint. The provided information does not state that authentication or any special privileges are required.
Which deployments are affected?
Datiphy Data Management Center versions v8.3.0 through v8.5.1 are affected. The issue is in the upload API endpoint, so deployments where that endpoint is reachable are exposed.
What is the impact of successful exploitation?
An attacker can use relative or absolute path sequences to write files outside the intended upload directory. The provided information does not specify which filesystem locations are writable or what follow-on impact may result.