Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an… (CVE-2026-76157)
Datiphy Data Management Center versions 8.3.0 through 8.5.1 contain a vulnerability where a critical function in the upload API endpoint lacks authentication. This allows unauthenticated remote attackers to upload arbitrary files. The vulnerability is classified as high severity due to the potential impact of unauthorized file uploads.
AI Analysis
Technical Summary
A missing authentication vulnerability exists in the upload API endpoint of Datiphy Data Management Center versions 8.3.0 through 8.5.1. This flaw allows unauthenticated remote attackers to upload arbitrary files because a critical function does not enforce authentication checks. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function). No patch or official fix information is provided in the available data.
Potential Impact
Unauthenticated attackers can upload arbitrary files to the affected system, potentially leading to unauthorized data manipulation, system compromise, or further exploitation depending on the nature of the uploaded files. The vulnerability is rated high severity, indicating significant risk if exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the upload API endpoint to trusted users or networks where possible and monitor for suspicious activity related to file uploads.
Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an… (CVE-2026-76157)
Description
Datiphy Data Management Center versions 8.3.0 through 8.5.1 contain a vulnerability where a critical function in the upload API endpoint lacks authentication. This allows unauthenticated remote attackers to upload arbitrary files. The vulnerability is classified as high severity due to the potential impact of unauthorized file uploads.
CVSS v4.0
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A missing authentication vulnerability exists in the upload API endpoint of Datiphy Data Management Center versions 8.3.0 through 8.5.1. This flaw allows unauthenticated remote attackers to upload arbitrary files because a critical function does not enforce authentication checks. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function). No patch or official fix information is provided in the available data.
Potential Impact
Unauthenticated attackers can upload arbitrary files to the affected system, potentially leading to unauthorized data manipulation, system compromise, or further exploitation depending on the nature of the uploaded files. The vulnerability is rated high severity, indicating significant risk if exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the upload API endpoint to trusted users or networks where possible and monitor for suspicious activity related to file uploads.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fgmq-h6gh-p5x7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76157"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a885f33acd9273b493f84b2
Added to database: 08/21/2026, 14:22:43 UTC
Last enriched: 08/21/2026, 15:07:20 UTC
Last updated: 08/21/2026, 15:07:20 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.