Skip to content
CVE Alert: CVE-2026-96272 – MacWarrior – clipbucket

CVE Alert: CVE-2026-96272 – MacWarrior – clipbucket

Redpacketsecurity •admin • September 23, 2026

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.

**Risk verdict:** High risk for exposed deployments; exploitation is feasible without an account or user action, but KEV and SSVC status are not provided, so active exploitation urgency cannot be confirmed.

**Why this matters:** A successful attack could expose sensitive records held by the application database, including credentials that may be reused elsewhere. A public technical write-up is referenced, but no PoC indicator or EPSS score is supplied; exploit maturity and current likelihood therefore remain uncertain.

**Most likely attack path:** An unauthenticated attacker sends crafted requests over the network to the affected function; low complexity and no special preconditions make opportunistic probing realistic. The assessed scope is unchanged, limiting direct impact beyond the application, though stolen credentials could support access to other systems if reused.

**Who is most exposed:** Internet-accessible photo or media-sharing sites running affected releases are most exposed, particularly community-hosted instances with public enabled.

Alert on unusual requests, especially malformed or repeated query parameters.

Review application and database logs for anomalous query delays or repeated time-based probes.

Check for unexpected exports or access to user and administrator account records.

Mitigation and prioritisation

Upgrade promptly to the vendor’s fixed release; verify the deployed code is patched.

If patching is delayed, restrict public access to or place the service behind a WAF with SQL-injection rules.

Review database access logs and rotate potentially exposed credentials; assess password reuse and administrator account activity.

Schedule changes through normal testing and change control, but expedite for internet-facing instances.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)