SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76157

HIGH · CVSS 8.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Datiphy Data Management Center versions 8.3.0 to 8.5.1 are vulnerable due to a lack of authentication in the upload API endpoint, enabling unauthenticated remote attackers to upload arbitrary files to the server. This vulnerability could lead to unauthorized access, data breaches, or server compromise. Organizations using affected versions should prioritize immediate remediation to mitigate potential exploitation risks.

CVE
CVE-2026-76157
Severity
HIGH
CVSS
8.8
EPSS
0.42%

Original NVD Description

Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.