PT-2026-22379 · Unknown · Clipbucket

Sy460129

·

Published

2026-02-27

·

Updated

2026-02-28

·

CVE-2026-28354

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.3
Description ClipBucket is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are susceptible to authorization flaws. Authenticated users can modify collection items belonging to other users. This is due to missing authorization checks when adding items via the /actions/add to collection.php endpoint and a broken ownership check in the removeItemFromCollection() function during item deletion via the /manage collections.php?mode=manage items... endpoint. Attackers can insert and remove items from collections they do not own.
Recommendations Update to version 5.5.3 #59 or later.

Exploit

Fix

IDOR

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-28354
GHSA-6WF8-RW5F-C9MV

Affected Products

Clipbucket