Back to all
2026-08-21

Datiphy Data Management Center - External Control of File Name or Path

ZUSOART ID
ZA-2026-07
CVE ID
CVE-2026-76158
Vulnerability Type
CWE-73: External Control of File Name or Path
CVSS 4.0 Base
9.3
Description

External  Control of File Name or Path in the upload API endpoint of Datiphy Data  Management Center from v8.3.0 through v8.5.1 allows a remote attacker to  write files to arbitrary locations outside the intended upload directory via  relative or absolute path sequences. 

‍

Vendor
Datiphy Inc.
Product
Category
Version affected
Data Management Center
from v8.3.0 through v8.5.1
Mitigations

Contact  Datiphy for version updates.

‍

Release date
2026-08-21
Credit

Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART

‍