CVE-2026-80138Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-08-25); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-25: 1Mentions · 2026-09-02: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-04: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-08-25: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-04: 108-2509-0209-04
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-251
Disclosure1
2026-09-021
Patch1
2026-09-041
Disclosure1
Full discourse3 posts
  • Adam N.@Qwesi_RED
    Disclosure

    🔐 CVE-2026-80138 | CVSS 9.8 Critical Found and responsibly disclosed an unauthenticated RCE in ClipBucket V5 via OS command injection. Technical write-up 👇 https://qwesired.com/blog/cve-2026-80138/ #CyberSecurity #CVE #AppSec

    Post summary

    CVE-2026-80138 was disclosed as a critical unauthenticated RCE in ClipBucket V5 triggered by OS command injection, with a technical write‑up link providing further details.

    0000089
    198 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-80138 (CVSS 9.8) ClipBucket V5 web installer allows unauthenticated RCE via php_cli_filepath parameter. Attackers can execute arbitrary commands remotely. Patch immediately if using ClipBucket V5. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/vjCXYSpdgJ

    Post summary

    The message highlights a critical CVE-2026-80138 in ClipBucket V5 that permits unauthenticated remote code execution through the php_cli_filepath parameter, and urges users to apply the patch immediately.

    0000056
    122 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-80138 Arbitrary Command Execution in ClipBucket V5 Installer via php_cli_filepath https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-80138

    Post summary

    The text is a brief disclosure of CVE-2026-80138, highlighting an arbitrary command execution flaw in ClipBucket V5 via php_cli_filepath, without additional PoC, exploit, or mitigation information.

    00000145
    4.1K followersView on X

Explore more