CVE-2026-32321 is an authenticated time-based blind SQL injection vulnerability affecting ClipBucket v5 before version 5.5.3 #80. The flaw is present in the actions/ajax.php endpoint due to insufficient sanitization of the userid parameter. An authenticated attacker can supply crafted input to the vulnerable parameter and induce arbitrary SQL query execution against the backend database. Because the issue is time-based blind SQL injection, exploitation does not require direct query output in the HTTP response; instead, an attacker can infer database contents and query behavior through response timing differences. The vulnerability can be used to extract sensitive database data and may facilitate compromise of privileged application accounts, including potential administrative account takeover.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
actions/ajax.php, especially those supplying anomalous or crafted userid values, and deploy WAF or reverse-proxy rules to detect and block SQL injection patterns where feasible. Audit database and administrative accounts for unauthorized changes, rotate credentials if compromise is suspected, and reduce database privileges used by the application to limit post-exploitation impact. These are temporary measures and do not replace upgrading to 5.5.3 #80 or later.Patch, then assume compromise.
726d68b0c9d4c702dce2691c2759b6bf84a1691f. Apply the official security update to all affected deployments and verify that the vulnerable actions/ajax.php handling of the userid parameter is no longer reachable in unpatched form.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.