CVE-2026-76158: Datiphy Inc Data Management Center
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Affected products
- Datiphy Inc Data Management Center: from v8.3.0, up to and including v8.5.1
Published 2026-08-21. Last modified 2026-08-26.