CVE-2026-80138 (matched: php)

  • Wednesday, 26th August, 2026
  • 10:07am

A security flaw has been found in the web installer for ClipBucket V5, a website content management tool some hosting clients may use. The installer does not properly check or filter a specific input setting (called php_cli_filepath) before using it to run system commands on the server.

This flaw does not require attackers to have login access to your site. Anyone who can send a web request to your site's installer page can submit a specially crafted request to run their own unauthorized commands on your hosting server.

These commands run with the same permissions as the web server user, which could let attackers access, modify, or delete files in your hosting account, or use your server for other malicious activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-80138

« Back