Vulnerability Description
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-76158?
CVE-2026-76158 is a documented vulnerability. External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the...
How severe is CVE-2026-76158?
CVSS scoring is not yet available for CVE-2026-76158. Check NVD for updates.
Is there a patch for CVE-2026-76158?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.