SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-76158

CRITICAL · CVSS 9.3 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Datiphy Data Management Center's upload API, versions 8.3.0 to 8.5.1, is vulnerable to external control of file names or paths, enabling remote attackers to write files to arbitrary locations outside the designated upload directory. This critical vulnerability could lead to unauthorized file access or system compromise. Organizations using affected versions should prioritize immediate remediation to mitigate potential exploitation risks.

CVE
CVE-2026-76158
Severity
CRITICAL
CVSS
9.3
EPSS
0.41%

Original NVD Description

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.