Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://zuso.ai/advisory |
|
History
Fri, 21 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory. | |
| Title | Datiphy Data Management Center - Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2026-08-21T01:47:44.338Z
Reserved: 2026-08-19T08:03:53.871Z
Link: CVE-2026-76157
No data.
Status : Received
Published: 2026-08-21T02:16:27.260
Modified: 2026-08-21T02:16:27.260
Link: CVE-2026-76157
No data.
OpenCVE Enrichment
Updated: 2026-08-21T04:00:13Z
Weaknesses