CVE-2026-32265Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.5 of the plugin to mitigate the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-18: 3Technical Details · 2026-03-18: 203-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32265 Unauthenticated Bucket Disclosure in Amazon S3 for Craft CMS Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32265

    Post summary

    The text announces CVE‑2026‑32265, a vulnerability that permits unauthenticated disclosure of Amazon S3 buckets in the Craft CMS plugin.

    0000061
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-32265 📊 Severity: 6.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32265 #CVE-2026-32265 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/DYcXeVey8z

    Post summary

    The tweet merely alerts about CVE-2026-32265 with generic severity details, offering no in-depth technical information, exploit details, or mitigation guidance.

    0000032
    104 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32265 The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets … https://www.cve.org/CVERecord?id=CVE-2026-32265

    Post summary

    The Amazon S3 for Craft CMS plugin is vulnerable (CVE‑2026‑32265) to unauthenticated bucket enumeration in versions 2.0.2–2.2.4; no exploit or patch details are provided.

    0000073
    56.7K followersView on X

Explore more