CVE-2026-76158

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
CVSS

No CVSS.

References
Link Resource
https://zuso.ai/advisory
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 03:16

Updated : 2026-08-26 16:55


NVD link : CVE-2026-76158

Mitre link : CVE-2026-76158

CVE.ORG link : CVE-2026-76158


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path