SQL Injection Vulnerability in ClipBucket Product by MacWarrior
CVE-2026-103766
Key Information:
- Vendor
Macwarrior
- Status
- Vendor
- CVE Published:
- 1 October 2026
Badges
What is CVE-2026-103766?
ClipBucket versions 5 through 5.5.3-#197 are susceptible to an SQL injection vulnerability that potentially allows authenticated users with ad_manager_access permission to manipulate SQL queries via the delete parameter in admin_area/ads_manager.php. By leveraging time-based blind payloads, attackers can extract sensitive user information, such as credentials and emails, or maliciously alter and remove records within the database. Prompt application of security patches and best practices are essential to mitigate exploitation risks.
Affected Version(s)
clipbucket-v5 0 <= 5.5.3-#197
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
