Path Traversal Vulnerability in ClipBucket Admin Template Editor by MacWarrior
CVE-2026-100372
Key Information:
- Vendor
Macwarrior
- Status
- Vendor
- CVE Published:
- 25 September 2026
Badges
What is CVE-2026-100372?
ClipBucket versions prior to 5.5.3-#197 contain a vulnerability in the admin template editor that allows authenticated administrators with manage_template_access permission to exploit directory traversal sequences. This flaw enables the modification of executable PHP files by traversing outside of the designated layout directory, which could lead to remote code execution as the web server user. It is critical for users to update to the latest version to mitigate this risk.
Affected Version(s)
clipbucket-v5 0 < 5.5.3-#197
clipbucket-v5 5.5.3-#197
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
