| ZUSOART ID |
ZA-2026-06 |
| CVE ID |
CVE-2026-76157 |
| Vulnerability Type |
CWE-306: Missing Authentication for Critical Function |
| CVSS 4.0 Base |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N (8.8) |
| Description |
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory. |
| Vendor |
Datiphy Inc. |
| Product |
| Category |
Version affected |
| Data Management Center |
from v8.3.0 through v8.5.1 |
|
| Product Support |
Contact Datiphy for version updates. |
| Release date |
2026/08/21 |
| Credit |
Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART |