CVE-2026-32266Disclosure

LOWCVSS 2.4 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-18: 2Technical Details · 2026-03-18: 103-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32266 Unauthenticated Google Cloud Storage Bucket Enumeration in Craft ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32266 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet simply announces CVE‑2026‑32266, noting it allows unauthenticated enumeration of Google Cloud Storage buckets, but no exploitation, patch, or further technical details are provided.

    0000039
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32266 📊 Severity: 2.4 🚨 Risk Level: Low 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32266 #CVE-2026-32266 #CVE #Low #Google #CyberSecurity #InfoSec https://t.co/1Ei1SswurL

    Post summary

    The tweet announces a new low‑severity CVE affecting Google, referencing the NVD but providing no technical, exploit, or patch information.

    0000033
    104 followersView on X

Explore more