CVE-2026-32265: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32265 is an information disclosure vulnerability in the Amazon S3 for Craft CMS plugin (craftcms/aws-s3) that allows unauthenticated users to enumerate S3 bucket names accessible to the plugin. The vulnerability affects plugin versions >= 2.0.2 and <= 2.2.4, and was disclosed on March 16, 2026, with a patch released as version 2.2.5. It carries a CVSS v4 base score of 6.9 (Medium) (GitHub Advisory).

Technical details

The root cause is improper access control (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) in the BucketsController->actionLoadBucketData() endpoint, which lacked an authentication check before processing requests. An unauthenticated attacker who possesses a valid CSRF token can send a POST request to this endpoint and receive a list of S3 bucket names the plugin is configured to access. The fix, applied in commit ef8904d, adds a $this->requireAdmin() call at the top of the actionLoadBucketData() method to enforce admin-level authentication before any data is returned (GitHub Advisory, Patch Commit).

Impact

Successful exploitation exposes the names of Amazon S3 buckets that the Craft CMS plugin is authorized to access, which could aid an attacker in reconnaissance and targeted attacks against those storage resources. There is no direct integrity or availability impact, and the vulnerability does not grant access to bucket contents. However, bucket name disclosure can facilitate further attacks such as bucket enumeration, targeted data exfiltration attempts, or social engineering (GitHub Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires obtaining a valid CSRF token from the target Craft CMS instance, which adds a minor barrier but is not a significant obstacle for a motivated attacker (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Craft CMS installation running the craftcms/aws-s3 plugin version >= 2.0.2 and <= 2.2.4 by inspecting publicly accessible pages or HTTP response headers.
  2. Obtain CSRF token: Load any public page of the target Craft CMS site and extract the CSRF token from the page source (typically found in a <meta> tag or a hidden form field).
  3. Craft malicious POST request: Send an HTTP POST request to the vulnerable endpoint (e.g., /index.php?p=actions/aws-s3/buckets/load-bucket-data or equivalent) with the Accept: application/json header and the extracted CSRF token included.
  4. Receive bucket list: Parse the JSON response, which will contain the list of S3 bucket names the plugin is configured to access, enabling further targeted reconnaissance against those buckets (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Network: Unexpected POST requests to the actions/aws-s3/buckets/load-bucket-data (or equivalent) endpoint from unauthenticated or anonymous sessions in web server access logs.
  • Logs: Craft CMS access logs showing POST requests to the BucketsController endpoint with Accept: application/json headers from IP addresses not associated with administrative users.
  • Logs: Repeated or automated requests to the bucket data endpoint from the same IP address or user agent, suggesting scripted enumeration activity.

Mitigation and workarounds

Update the craftcms/aws-s3 Composer package to version 2.2.5 or later, which adds an $this->requireAdmin() check to the vulnerable endpoint. No configuration-based workaround is available; upgrading is the only effective remediation. Administrators can also restrict access to Craft CMS action endpoints at the web server or firewall level as a temporary measure while planning the upgrade (GitHub Advisory, Patch Commit).

Community reactions

The vulnerability was reported by a researcher credited as "Neosprings" and published by "angrybrad" to the craftcms/aws-s3 repository on March 16, 2026. No significant broader media coverage or notable community commentary beyond the advisory itself has been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management