OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103766

HIGH · CVSS 7.2 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

ClipBucket versions 5 through 5.5.3-#197 are vulnerable to an SQL injection flaw that enables authenticated users with ad_manager_access permission to manipulate SQL queries through the delete parameter in admin_area/ads_manager.php. This vulnerability allows attackers to execute time-based blind payloads, potentially leading to the extraction of sensitive user credentials and emails or unauthorized modification and deletion of records. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103766
Severity
HIGH
CVSS
7.2
EPSS
0.36%

Original NVD Description

ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.