CVE-2026-76158

Summary

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

Affected Software

VendorProductVersion RangeStatus
Datiphy Inc.Data Management Centerv8.3.0 <= v8.5.1affected

Weaknesses

  • CWE-73: CWE-73 External control of file name or path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References