Skip to content
Critical SQL Injection Vulnerability in ClipBucket v5 Disclosed

Critical SQL Injection Vulnerability in ClipBucket v5 Disclosed

First seen 23 Sep 2026, 19:54 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 20:58 UTC
  • CVE-2026-96272 allows unauthenticated SQL injection attacks on ClipBucket v5.
  • Sensitive user data, including credentials and admin hashes, can be extracted.
  • Immediate patching or access restrictions are recommended to mitigate risks.

A blind SQL injection vulnerability (CVE-2026-96272) has been identified in ClipBucket v5 prior to version 5.5.3-#182. The vulnerability allows unauthenticated attackers to exploit the photo endpoint by sending crafted requests that include unsanitized query parameters. This could lead to the extraction of sensitive user data, including credentials and administrator password hashes, potentially resulting in account takeovers. The risk is particularly high for internet-accessible photo or media-sharing sites running the affected versions. While the vulnerability is confirmed, the urgency for active exploitation remains uncertain as no proof-of-concept or exploitation in the wild has been reported. Administrators are advised to upgrade to the patched version promptly or implement security measures such as restricting public access. Monitoring for unusual requests and reviewing logs for anomalies is also recommended.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
CVE-2026-96272 published
A blind SQL injection vulnerability in ClipBucket v5 was disclosed, affecting versions before 5.5.3-#182.
Redpacketsecurity
2026-09-23
Vulnerability details released
The vulnerability allows unauthenticated attackers to exploit the photo endpoint for sensitive data extraction.
hackmd.io

More articles in this cluster (2)

Following this threat?

Track CVE-2026-96272 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed