{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-26997",
        "tracking": {
            "current_release_date": "2026-03-23T01:02:19.347926Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-26997",
            "initial_release_date": "2026-02-27T19:39:01.425657Z",
            "revision_history": [
                {
                    "date": "2026-02-27T19:39:01.425657Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T19:39:03.559432Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-27T20:26:14.422279Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T20:26:17.838608Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-27T20:38:48.407632Z",
                    "number": "5",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-02-28T07:35:11.380783Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T14:14:05.291317Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-28T14:14:10.267589Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T11:03:08.300929Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (37).| Products created (2).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-03T11:03:17.527427Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T20:25:14.310479Z",
                    "number": "11",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1).| Exploits created (1)."
                },
                {
                    "date": "2026-03-03T20:25:20.229455Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:42:52.015730Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:42:54.889556Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "14"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=5.3|<5.5.3-59",
                                "product": {
                                    "name": "vers:unknown/>=5.3|<5.5.3-59",
                                    "product_id": "CSAFPID-5757119",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "clipbucket"
                    }
                ],
                "category": "vendor",
                "name": "oxygenz"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<5.5.3#59",
                                "product": {
                                    "name": "vers:unknown/<5.5.3#59",
                                    "product_id": "CSAFPID-5736300"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "clipbucket-v5"
                    }
                ],
                "category": "vendor",
                "name": "MacWarrior"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3",
                                "product": {
                                    "name": "vers:unknown/5.3",
                                    "product_id": "CSAFPID-3652363"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.3.1",
                                "product": {
                                    "name": "vers:unknown/5.3.1",
                                    "product_id": "CSAFPID-3652364"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.0",
                                "product": {
                                    "name": "vers:unknown/5.4.0",
                                    "product_id": "CSAFPID-3652365"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.4.1",
                                "product": {
                                    "name": "vers:unknown/5.4.1",
                                    "product_id": "CSAFPID-3652366"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.0",
                                "product": {
                                    "name": "vers:unknown/5.5.0",
                                    "product_id": "CSAFPID-3652367"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.1",
                                "product": {
                                    "name": "vers:unknown/5.5.1",
                                    "product_id": "CSAFPID-5104756"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2",
                                "product": {
                                    "name": "vers:unknown/5.5.2",
                                    "product_id": "CSAFPID-5119468"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#103",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#103",
                                    "product_id": "CSAFPID-5104757"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#106",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#106",
                                    "product_id": "CSAFPID-5104758"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#114",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#114",
                                    "product_id": "CSAFPID-5104759"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#117",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#117",
                                    "product_id": "CSAFPID-5104760"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#120",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#120",
                                    "product_id": "CSAFPID-5104761"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#123",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#123",
                                    "product_id": "CSAFPID-5104762"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#129",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#129",
                                    "product_id": "CSAFPID-5104763"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#133",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#133",
                                    "product_id": "CSAFPID-5104764"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#135",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#135",
                                    "product_id": "CSAFPID-5104765"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#138",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#138",
                                    "product_id": "CSAFPID-5104766"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#140",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#140",
                                    "product_id": "CSAFPID-5104767"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#147",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#147",
                                    "product_id": "CSAFPID-5107396"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#152",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#152",
                                    "product_id": "CSAFPID-5165584"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#162",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#162",
                                    "product_id": "CSAFPID-5215588"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#163",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#163",
                                    "product_id": "CSAFPID-5215589"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#164",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#164",
                                    "product_id": "CSAFPID-5355595"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#182",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#182",
                                    "product_id": "CSAFPID-5355596"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#187",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#187",
                                    "product_id": "CSAFPID-5355597"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#25",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#25",
                                    "product_id": "CSAFPID-5104768"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#38",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#38",
                                    "product_id": "CSAFPID-5104769"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#4",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#4",
                                    "product_id": "CSAFPID-5104770"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#45",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#45",
                                    "product_id": "CSAFPID-5104771"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#58",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#58",
                                    "product_id": "CSAFPID-5104772"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#69",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#69",
                                    "product_id": "CSAFPID-5104773"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#74",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#74",
                                    "product_id": "CSAFPID-5104774"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#82",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#82",
                                    "product_id": "CSAFPID-5104775"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#86",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#86",
                                    "product_id": "CSAFPID-5104776"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#90",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#90",
                                    "product_id": "CSAFPID-5104777"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.2-#98",
                                "product": {
                                    "name": "vers:unknown/5.5.2-#98",
                                    "product_id": "CSAFPID-5104778"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.3-#10",
                                "product": {
                                    "name": "vers:unknown/5.5.3-#10",
                                    "product_id": "CSAFPID-5601923"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.3-#46",
                                "product": {
                                    "name": "vers:unknown/5.5.3-#46",
                                    "product_id": "CSAFPID-5755739"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/5.5.3-#50",
                                "product": {
                                    "name": "vers:unknown/5.5.3-#50",
                                    "product_id": "CSAFPID-5755740"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "clipbucket-v5"
                    }
                ],
                "category": "vendor",
                "name": "macwarrior"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-26997",
            "cwe": {
                "id": "CWE-79",
                "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-26997"
                },
                {
                    "category": "description",
                    "text": "ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-26997"
                },
                {
                    "category": "description",
                    "text": "ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-26997.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.0001",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "2.0",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "3.7",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is exploit data available from source Nvd, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5736300",
                    "CSAFPID-3652363",
                    "CSAFPID-3652364",
                    "CSAFPID-3652365",
                    "CSAFPID-3652366",
                    "CSAFPID-3652367",
                    "CSAFPID-5104756",
                    "CSAFPID-5104757",
                    "CSAFPID-5104758",
                    "CSAFPID-5104759",
                    "CSAFPID-5104760",
                    "CSAFPID-5104761",
                    "CSAFPID-5104762",
                    "CSAFPID-5104763",
                    "CSAFPID-5104764",
                    "CSAFPID-5104765",
                    "CSAFPID-5104766",
                    "CSAFPID-5104767",
                    "CSAFPID-5104768",
                    "CSAFPID-5104769",
                    "CSAFPID-5104770",
                    "CSAFPID-5104771",
                    "CSAFPID-5104772",
                    "CSAFPID-5104773",
                    "CSAFPID-5104774",
                    "CSAFPID-5104775",
                    "CSAFPID-5104776",
                    "CSAFPID-5104777",
                    "CSAFPID-5104778",
                    "CSAFPID-5107396",
                    "CSAFPID-5119468",
                    "CSAFPID-5165584",
                    "CSAFPID-5215588",
                    "CSAFPID-5215589",
                    "CSAFPID-5355595",
                    "CSAFPID-5355596",
                    "CSAFPID-5355597",
                    "CSAFPID-5601923",
                    "CSAFPID-5755739",
                    "CSAFPID-5755740",
                    "CSAFPID-5757119"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-26997"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/26xxx/CVE-2026-26997.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26997"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-26997"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-26997"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-26997.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-97r6-4hmx-hcrh"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/MacWarrior/clipbucket-v5/commit/2da4c8e41f9e4baf47ff89f8a674fbe9b63ac76d"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26997.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26997"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-3652363",
                        "CSAFPID-3652364",
                        "CSAFPID-3652365",
                        "CSAFPID-3652366",
                        "CSAFPID-3652367",
                        "CSAFPID-5104756",
                        "CSAFPID-5104757",
                        "CSAFPID-5104758",
                        "CSAFPID-5104759",
                        "CSAFPID-5104760",
                        "CSAFPID-5104761",
                        "CSAFPID-5104762",
                        "CSAFPID-5104763",
                        "CSAFPID-5104764",
                        "CSAFPID-5104765",
                        "CSAFPID-5104766",
                        "CSAFPID-5104767",
                        "CSAFPID-5104768",
                        "CSAFPID-5104769",
                        "CSAFPID-5104770",
                        "CSAFPID-5104771",
                        "CSAFPID-5104772",
                        "CSAFPID-5104773",
                        "CSAFPID-5104774",
                        "CSAFPID-5104775",
                        "CSAFPID-5104776",
                        "CSAFPID-5104777",
                        "CSAFPID-5104778",
                        "CSAFPID-5107396",
                        "CSAFPID-5119468",
                        "CSAFPID-5165584",
                        "CSAFPID-5215588",
                        "CSAFPID-5215589",
                        "CSAFPID-5355595",
                        "CSAFPID-5355596",
                        "CSAFPID-5355597",
                        "CSAFPID-5601923",
                        "CSAFPID-5736300",
                        "CSAFPID-5755739",
                        "CSAFPID-5755740",
                        "CSAFPID-5757119"
                    ]
                }
            ],
            "title": "CVE-2026-26997"
        }
    ]
}