Security Advisory

CVE-2026-76158

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-21 02:02:23
Last updated 2026-08-21 13:01:03
Assigner ZUSO ART
CVSS score 9.3
State PUBLISHED

Description

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.