← Back to search

CVE-2026-77929

8.8 HIGHpublic exploit available

Published 2026-09-18 · Updated 2026-09-22

AI risk analysis

Summary
This vulnerability allows authenticated users to upload a PHP file that can be executed remotely, leading to potential full system compromise.
Exploitability
Exploitation is relatively straightforward for an attacker who can authenticate, as the flaw lies in the file extension validation process.
Blast radius
If exploited, the impact could be severe, as it allows for remote code execution on the server hosting the ClipBucket application.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to ClipBucket v5.5.3-#182 or later.
rceauth-requiredweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.