
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32265 is an information disclosure vulnerability in the Amazon S3 for Craft CMS plugin (craftcms/aws-s3) that allows unauthenticated users to enumerate S3 bucket names accessible to the plugin. The vulnerability affects plugin versions >= 2.0.2 and <= 2.2.4, and was disclosed on March 16, 2026, with a patch released as version 2.2.5. It carries a CVSS v4 base score of 6.9 (Medium) (GitHub Advisory).
The root cause is improper access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the BucketsController->actionLoadBucketData() endpoint, which lacked an authentication check before processing requests. An unauthenticated attacker who possesses a valid CSRF token can send a POST request to this endpoint and receive a list of S3 bucket names the plugin is configured to access. The fix, applied in commit ef8904d, adds a $this->requireAdmin() call at the top of the actionLoadBucketData() method to enforce admin-level authentication before any data is returned (GitHub Advisory, Patch Commit).
Successful exploitation exposes the names of Amazon S3 buckets that the Craft CMS plugin is authorized to access, which could aid an attacker in reconnaissance and targeted attacks against those storage resources. There is no direct integrity or availability impact, and the vulnerability does not grant access to bucket contents. However, bucket name disclosure can facilitate further attacks such as bucket enumeration, targeted data exfiltration attempts, or social engineering (GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires obtaining a valid CSRF token from the target Craft CMS instance, which adds a minor barrier but is not a significant obstacle for a motivated attacker (GitHub Advisory).
craftcms/aws-s3 plugin version >= 2.0.2 and <= 2.2.4 by inspecting publicly accessible pages or HTTP response headers.<meta> tag or a hidden form field)./index.php?p=actions/aws-s3/buckets/load-bucket-data or equivalent) with the Accept: application/json header and the extracted CSRF token included.actions/aws-s3/buckets/load-bucket-data (or equivalent) endpoint from unauthenticated or anonymous sessions in web server access logs.BucketsController endpoint with Accept: application/json headers from IP addresses not associated with administrative users.Update the craftcms/aws-s3 Composer package to version 2.2.5 or later, which adds an $this->requireAdmin() check to the vulnerable endpoint. No configuration-based workaround is available; upgrading is the only effective remediation. Administrators can also restrict access to Craft CMS action endpoints at the web server or firewall level as a temporary measure while planning the upgrade (GitHub Advisory, Patch Commit).
The vulnerability was reported by a researcher credited as "Neosprings" and published by "angrybrad" to the craftcms/aws-s3 repository on March 16, 2026. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."