VulnerabilityCVE-2026-28354

CVE-2026-28354: ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify ano

NVD/CVE · [email protected]2/28/2026, 1:21:41 AM
View Original Source

Summary

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization checks and delete item (/manage_collections.php?mode=manage_items...) due to a broken ownership check in removeItemFromCollection(). As a result, attackers can insert and remove items from collections they do not own. Version 5.5.3 #59 fixes the issue.

Tags

#CVE-2026-28354#cve

Metadata

Article ID
#374
Source
NVD/CVE
Scraped At
3/2/2026, 7:10:21 AM
URL Hash
1445204cf8f9e55d…