CVE-2026-28354 | MacWarrior clipbucket-v5 up to up to 5.5.2 add_to_collection.php removeItemFromCollection authorization (GHSA-6wf8-rw5f-c9mv / EUVD-2026-9062)
A vulnerability categorized as problematic has been discovered in MacWarrior clipbucket-v5 up to up to 5.5.2. Impacted is the function removeItemFromCollection of the file /actions/add_to_collection.php. Such manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-28354. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.