CVE-2026-32268: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32268 is a Missing Authorization (CWE-862) vulnerability in the Azure Blob Storage plugin for Craft CMS that allows unauthenticated users to enumerate cloud storage buckets and potentially expose sensitive Azure error message data. It affects plugin versions >= 2.0.0-beta.1 through <= 2.1.0 (Composer package craftcms/azure-blob). The vulnerability was published on March 16, 2026, by researcher Neosprings via GitHub Advisory GHSA-q6fm-p73f-x862, and was added to the NVD on March 18, 2026. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) in the DefaultController->actionLoadContainerData() endpoint of the craftcms/azure-blob plugin. Any unauthenticated user who possesses a valid CSRF token can send a POST request to this endpoint and receive a list of Azure Blob Storage containers (buckets) that the plugin is configured to access. The fix, applied in commit cf69db4, adds a single $this->requireAdmin() call before the existing requirePostRequest() and requireAcceptsJson() checks, confirming that no authentication gate existed previously. Additionally, Azure's verbose error responses can leak supplementary sensitive details such as account names and resource paths when malformed or edge-case requests are submitted (GitHub Advisory, Fix Commit).

Impact

Successful exploitation results in unauthorized disclosure of Azure Blob Storage container names accessible to the plugin, which can reveal the organization's cloud storage architecture and naming conventions. Azure error messages triggered by crafted requests may further expose account names, resource paths, or subscription-level details, providing an attacker with reconnaissance data to facilitate lateral movement within the Azure environment. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.034% (0.0005 raw), placing it in the 10th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid CSRF token — obtainable by visiting the Craft CMS site — making it relatively low-effort for an attacker with network access to the application.

Exploitation steps

  1. Reconnaissance: Identify Craft CMS installations using the craftcms/azure-blob plugin (versions 2.0.0-beta.1 through 2.1.0) via web fingerprinting tools or by inspecting publicly accessible Craft CMS sites.
  2. Obtain CSRF token: Visit any page of the target Craft CMS site to retrieve a valid CSRF token from the page source or cookies (e.g., from the CRAFT_CSRF_TOKEN cookie or a hidden form field).
  3. Craft malicious POST request: Send an authenticated-looking POST request to the DefaultController->actionLoadContainerData() endpoint (typically at a path such as /actions/azure-blob/default/load-container-data) with the CSRF token included in the request headers or body, and with Content-Type: application/json or Accept: application/json.
  4. Enumerate buckets: Parse the JSON response, which will contain a list of Azure Blob Storage container names accessible to the plugin, revealing the cloud storage structure.
  5. Harvest Azure error data: Submit edge-case or malformed requests to the same endpoint to trigger Azure SDK error messages, which may disclose additional sensitive details such as storage account names, resource paths, or connection metadata (GitHub Advisory, Fix Commit).

Indicators of compromise

  • Network: Unexpected POST requests to the Craft CMS endpoint path matching /actions/azure-blob/default/load-container-data (or equivalent) originating from unauthenticated or anonymous sessions; repeated requests from the same IP with varying CSRF tokens.
  • Logs: Craft CMS access logs showing POST requests to the actionLoadContainerData endpoint from users with no authenticated session; Azure SDK error responses logged server-side containing account or resource path details.
  • Application: Craft CMS application logs showing DefaultController::actionLoadContainerData invocations without an associated admin session context.

Mitigation and workarounds

Update the craftcms/azure-blob Composer package to version 2.1.1 or later, which adds a $this->requireAdmin() authorization check to the vulnerable endpoint (Fix Commit, GitHub Advisory). As an interim workaround prior to patching, implement WAF or network-level rules to block unauthenticated POST requests to the actionLoadContainerData endpoint. Additionally, review web server and Craft CMS access logs to determine whether the endpoint was accessed by unauthorized users, and rotate Azure Blob Storage credentials if unauthorized access is suspected.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management