Junglewise Threat Intelligence

CVE-2026-76157: Datiphy Data Management Center authentication bypass in upload API

CVE-2026-76157 · Severity: info · Published 2026-08-21

Technologies: Datiphy Data Management Center. Vendors: Datiphy.

Executive brief

Datiphy Data Management Center is a data management platform used to handle file uploads and data storage. An unauthenticated attacker can upload arbitrary files to the server without proper authentication, potentially leading to malicious file placement, service disruption, or further system compromise.

Technical details

The vulnerability is a missing authentication control in the upload API endpoint of Datiphy Data Management Center. The upload function fails to validate user authentication before accepting file uploads, allowing an unauthenticated remote attacker to reach and exploit this critical endpoint directly over the network. An attacker can upload arbitrary files to the server's configured upload directory without providing valid credentials. Affected versions range from v8.3.0 through v8.5.1. A patch is likely available in versions after v8.5.1.

Affected products

  • Datiphy Data Management Center v8.3.0 through v8.5.1

Timeline

  • 2026-08-21: disclosed

References

Related threats