CVE-2026-76158: Datiphy Inc Data Management Center

Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

Affected products

  • Datiphy Inc Data Management Center: from v8.3.0, up to and including v8.5.1

Published 2026-08-21. Last modified 2026-08-26.