cbcvebase.

Datiphy Inc Data Management Center vulnerabilities

4 known vulnerabilities affecting datiphy_inc/data_management_center.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-76156P2CRITICALCVSS 9.4≥ v8.3.0, ≤ v8.5.12026-08-21
CVE-2026-76156 [CRITICAL] CWE-78 CVE-2026-76156: OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5. OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.
nvd
CVE-2026-76157P2HIGHCVSS 8.8≥ v8.3.0, ≤ v8.5.12026-08-21
CVE-2026-76157 [HIGH] CWE-306 CVE-2026-76157: Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.
nvd
CVE-2026-76158P2CRITICALCVSS 9.3≥ v8.3.0, ≤ v8.5.12026-08-21
CVE-2026-76158 [CRITICAL] CWE-73 CVE-2026-76158: External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center f External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
nvd
CVE-2026-76155P2CRITICALCVSS 9.3≥ v8.3.0, ≤ v8.5.12026-08-21
CVE-2026-76155 [CRITICAL] CWE-1392 CVE-2026-76155: Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a rem Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.
nvd
Datiphy Inc Data Management Center vulnerabilities | cvebase