PT-2026-99100 · Unknown · Clipbucket

·

CVE-2026-100372

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.3-#197
Description A path traversal issue exists in the admin template editor. Authenticated administrators with manage template access permission can use directory traversal sequences in the folder parameter to access locations outside the layout directory. This allows the modification of executable PHP files, potentially leading to remote code execution as the web server user.
Recommendations Update to version 5.5.3-#197 or later.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100372

Affected Products

Clipbucket