CVE-2026-77929: ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint

Published Sep 18, 2026
·
Updated

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.

Affected Software

1 affected component
ClipBucket ClipBucket<5.5.3-#182

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ClipBucket to a version that resolves this vulnerability.

    Fixed in 5.5.3-#182
  2. Compensating control

    Restrict access to the photo upload endpoint to trusted/authenticated users and apply network-layer controls (e.g., IP allowlisting/WAF rules) to reduce exposure of the vulnerable upload functionality.

Event History

Sep 18, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated ClipBucket user who can use the photo upload endpoint can exploit it. No user interaction is required.

2

What does an attacker need to upload?

The attacker needs to upload a file with a .php extension that also contains valid image magic bytes, allowing it to pass MIME validation while retaining the PHP extension on disk.

3

Under what deployment condition does uploaded code execute?

Execution occurs when the uploaded file is retrieved in an environment where PHP-FPM processes the retained .php file as PHP.

4

Which versions are affected and what is the available fix?

ClipBucket v5 releases before 5.5.3-#182 are affected. Upgrade to 5.5.3-#182 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203