HIGHCVESeptember 18, 2026
CVE-2026-77929, ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows...
DecipherU Intelligence aggregates cybersecurity developments from government databases, official filings, and authoritative sources. The summary below is written by DecipherU and does not represent the views of the original source. For full details, follow the source link.
Summary
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.
Relevant Roles
incident-respondersoc-analystsecurity-engineer
For the full cve details, visit the original source.
Read Original Source: nvd.nist.govSource: nvd.nist.gov, September 18, 2026. This summary is DecipherU's original writing. For complete details, follow the source link above. This page is for informational purposes only and does not constitute security advice.
Sources
- NIST National Vulnerability Database (NVD) · Authoritative CVE records and CVSS scoring.
- CISA Advisories · Public-domain US Cybersecurity and Infrastructure Security Agency alerts.
- DecipherU Live Feeds · DecipherU aggregates and curates these cybersecurity intelligence items.
Last verified: September 18, 2026?Report an inaccuracy