2026-08-21

Datiphy Data Management Center - External Control of File Name or Path

ZUSOART ID ZA-2026-07
CVE ID CVE-2026-76158
Vulnerability Type CWE-73: External Control of File Name or Path
CVSS 4.0 Base CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H (9.3)
Description External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Vendor Datiphy Inc.
Product
Category Version affected
Data Management Center from v8.3.0 through v8.5.1
Product Support Contact Datiphy for version updates.
Release date 2026/08/21
Credit Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART
top