
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32268 is a Missing Authorization (CWE-862) vulnerability in the Azure Blob Storage plugin for Craft CMS that allows unauthenticated users to enumerate cloud storage buckets and potentially expose sensitive Azure error message data. It affects plugin versions >= 2.0.0-beta.1 through <= 2.1.0 (Composer package craftcms/azure-blob). The vulnerability was published on March 16, 2026, by researcher Neosprings via GitHub Advisory GHSA-q6fm-p73f-x862, and was added to the NVD on March 18, 2026. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory).
The root cause is a missing authorization check (CWE-862) in the DefaultController->actionLoadContainerData() endpoint of the craftcms/azure-blob plugin. Any unauthenticated user who possesses a valid CSRF token can send a POST request to this endpoint and receive a list of Azure Blob Storage containers (buckets) that the plugin is configured to access. The fix, applied in commit cf69db4, adds a single $this->requireAdmin() call before the existing requirePostRequest() and requireAcceptsJson() checks, confirming that no authentication gate existed previously. Additionally, Azure's verbose error responses can leak supplementary sensitive details such as account names and resource paths when malformed or edge-case requests are submitted (GitHub Advisory, Fix Commit).
Successful exploitation results in unauthorized disclosure of Azure Blob Storage container names accessible to the plugin, which can reveal the organization's cloud storage architecture and naming conventions. Azure error messages triggered by crafted requests may further expose account names, resource paths, or subscription-level details, providing an attacker with reconnaissance data to facilitate lateral movement within the Azure environment. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.034% (0.0005 raw), placing it in the 10th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a valid CSRF token — obtainable by visiting the Craft CMS site — making it relatively low-effort for an attacker with network access to the application.
craftcms/azure-blob plugin (versions 2.0.0-beta.1 through 2.1.0) via web fingerprinting tools or by inspecting publicly accessible Craft CMS sites.CRAFT_CSRF_TOKEN cookie or a hidden form field).DefaultController->actionLoadContainerData() endpoint (typically at a path such as /actions/azure-blob/default/load-container-data) with the CSRF token included in the request headers or body, and with Content-Type: application/json or Accept: application/json./actions/azure-blob/default/load-container-data (or equivalent) originating from unauthenticated or anonymous sessions; repeated requests from the same IP with varying CSRF tokens.actionLoadContainerData endpoint from users with no authenticated session; Azure SDK error responses logged server-side containing account or resource path details.DefaultController::actionLoadContainerData invocations without an associated admin session context.Update the craftcms/azure-blob Composer package to version 2.1.1 or later, which adds a $this->requireAdmin() authorization check to the vulnerable endpoint (Fix Commit, GitHub Advisory). As an interim workaround prior to patching, implement WAF or network-level rules to block unauthenticated POST requests to the actionLoadContainerData endpoint. Additionally, review web server and Craft CMS access logs to determine whether the endpoint was accessed by unauthorized users, and rotate Azure Blob Storage credentials if unauthorized access is suspected.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."