cbcvebase.
CVE-2026-76158
published 2026-08-21

CVE-2026-76158: External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write…

PriorityP263critical9.3CVSS 4.0
AVNACLATNPRNUINVCNVIHVAHSCNSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.52%
42.0th percentile
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

Affected

1 ranges
VendorProductVersion rangeFixed in
datiphy_incdata_management_centerv8.3.0 – v8.5.1—
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.