CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-67418

Critical · CVSS 9.8

ClipBucket — Hardcoded Default Credentials / Improper Access Control (CWE-798)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-798

Description

ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the application.

Search profile — drives PoC discovery

Symbols admindefault credentialsadministrative panelhardcoded passwordClipBucket loginadmin panel authentication
Keywords CVE-2025-67418ClipBucket 5.5.2hardcoded credentialsdefault admin credentialsClipBucket admin panelClipBucket authentication bypassClipBucket PoCClipBucket exploitCWE-798 ClipBucket
Versions: 5.5.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z