Junglewise Threat Intelligence

CVE-2026-96272: ClipBucket SQL injection in photo search

CVE-2026-96272 · Severity: high · CVSS 7.5 · Published 2026-09-23

Technologies: MacWarrior ClipBucket. Vendors: MacWarrior.

Executive brief

ClipBucket is an open-source video hosting platform. An unauthenticated attacker can inject malicious SQL code through the photo search endpoint to extract sensitive data such as user credentials, email addresses, and administrator password hashes, leading to account takeover and unauthorized access.

Technical details

A blind SQL injection vulnerability exists in the photo search endpoint (photos.class.php) where user-supplied query parameters are passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques without authentication. Successful exploitation allows extraction of user credentials and password hashes from the database, enabling account takeover.

Affected products

  • MacWarrior ClipBucket before 5.5.3-#182

Timeline

  • 2026-09-23: disclosed

References

Related threats