CVE-2026-77927: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in MacWarrior clipbucket-v5
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.
AI Analysis
Technical Summary
CVE-2026-77927 is a blind SQL injection vulnerability in ClipBucket v5 through 5.5.3. Authenticated users can exploit this by submitting the check_photo parameter as an array, bypassing the clean_requests() sanitization function in ClipBucket.class.php. Unsanitized array elements are passed through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are directly interpolated into a SQL query. This enables time-based blind SQL injection attacks to extract sensitive data from the database, including credential hashes.
Potential Impact
An attacker with authenticated access can exploit this vulnerability to perform time-based blind SQL injection, allowing extraction of arbitrary data from the database. This includes sensitive information such as credential hashes, which could lead to further compromise if leveraged.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user privileges to minimize exposure and monitor for suspicious activity related to photo management functions.
CVE-2026-77927: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in MacWarrior clipbucket-v5
Description
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.
CVSS v4.0
Score 7.1high
Affected software
MacWarrior
clipbucket-v5
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-77927 is a blind SQL injection vulnerability in ClipBucket v5 through 5.5.3. Authenticated users can exploit this by submitting the check_photo parameter as an array, bypassing the clean_requests() sanitization function in ClipBucket.class.php. Unsanitized array elements are passed through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are directly interpolated into a SQL query. This enables time-based blind SQL injection attacks to extract sensitive data from the database, including credential hashes.
Potential Impact
An attacker with authenticated access can exploit this vulnerability to perform time-based blind SQL injection, allowing extraction of arbitrary data from the database. This includes sensitive information such as credential hashes, which could lead to further compromise if leveraged.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict authenticated user privileges to minimize exposure and monitor for suspicious activity related to photo management functions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-21T17:52:36.079Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aad4b7355bf5e2cf51f5ecc
Added to database: 09/18/2026, 14:32:19 UTC
Last enriched: 09/18/2026, 14:46:56 UTC
Last updated: 09/19/2026, 00:08:06 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.