Executive brief
ClipBucket, a video sharing and management platform, is shipped with hardcoded default administrative credentials. This allows any unauthorized person on the internet to log in to the management console with full administrative privileges. An attacker could take complete control of the application, access private user data, or shut down the service entirely.
Technical details
ClipBucket versions 5.3 through 5.5.2 contain hardcoded default administrative credentials (CWE-798). This vulnerability allows a remote, unauthenticated attacker to access the administrative interface by providing the static, pre-configured credentials. Successful exploitation grants the attacker full administrative control over the application, including the ability to modify content, manage users, and access sensitive data. The issue stems from improper access control during the deployment phase where default accounts are not forcibly rotated or randomized. Users are advised to change default passwords immediately upon installation.
Affected products
- Oxygenz ClipBucket 5.3 through 5.5.2
Timeline
- 2025-12-22: advisory: Initial NVD publication date
- 2025-12-22: disclosed: Public disclosure via Medium article