CRITICAL
9.8 CVE-2026-80138 Published 25 Aug 2026
ClipBucket V5 Web Installer Command Injection
Worried this affects one of your servers?
ClipBucket V5's web installer contains a critical security flaw.
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution.
Unauthenticated attackers can exploit this vulnerability by submitting a crafted POST request to the installer with a malicious php_cli_filepath value, allowing them to execute arbitrary commands as the web server user.
Reference: CVE-2026-80138 on NVD
← Back to Security News