PT-2026-95412 · Unknown · Clipbucket

·

CVE-2026-77929

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.3-#182
Description Authenticated users can achieve remote code execution by uploading a PHP file containing valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation. This allows a .php extension controlled by the attacker to remain on the disk and execute as PHP via PHP-FPM when the file is retrieved.
Recommendations Update to version 5.5.3-#182 or later. As a temporary mitigation, restrict access to the photo upload endpoint or disable the FileUpload::manageFile() function until the update is applied.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77929

Affected Products

Clipbucket