Executive brief
Datiphy Data Management Center is a data management platform used to handle file uploads and data storage. An unauthenticated attacker can upload arbitrary files to the server without proper authentication, potentially leading to malicious file placement, service disruption, or further system compromise.
Technical details
The vulnerability is a missing authentication control in the upload API endpoint of Datiphy Data Management Center. The upload function fails to validate user authentication before accepting file uploads, allowing an unauthenticated remote attacker to reach and exploit this critical endpoint directly over the network. An attacker can upload arbitrary files to the server's configured upload directory without providing valid credentials. Affected versions range from v8.3.0 through v8.5.1. A patch is likely available in versions after v8.5.1.
Affected products
- Datiphy Data Management Center v8.3.0 through v8.5.1
Timeline
- 2026-08-21: disclosed