CRITICAL 9.8 CVE-2026-80138 Published 25 Aug 2026

ClipBucket V5 Web Installer Command Injection

Worried this affects one of your servers?

ClipBucket V5's web installer contains a critical security flaw.

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution.

Unauthenticated attackers can exploit this vulnerability by submitting a crafted POST request to the installer with a malicious php_cli_filepath value, allowing them to execute arbitrary commands as the web server user.

Reference: CVE-2026-80138 on NVD

← Back to Security News