Back to all
2026-08-21

Datiphy Data Management Center - Missing Authentication for Critical Function

ZUSOART ID
ZA-2026-06
CVE ID
CVE-2026-76157
Vulnerability Type
CWE-306: Missing Authentication for Critical Function
CVSS 4.0 Base
8.8
Description

Missing  authentication for a critical function in the upload API endpoint of Datiphy  Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated  remote attacker to upload arbitrary files to the server's configured upload  directory.

‍

Vendor
Datiphy Inc.
Product
Category
Version affected
Data Management Center
from v8.3.0 through v8.5.1
Mitigations

Contact  Datiphy for version updates.

‍

Release date
2026-08-21
Credit

Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART

‍