{"id":"CVE-2026-32266","summary":"Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability","details":"The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController-\u003eactionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.","aliases":["GHSA-67cr-jmh8-4jpq"],"modified":"2026-08-07T11:50:56.866603627Z","published":"2026-03-18T03:46:00.150Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32266.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32266.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/google-cloud/security/advisories/GHSA-67cr-jmh8-4jpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32266"},{"type":"FIX","url":"https://github.com/craftcms/google-cloud/commit/651bacaa5f5fd7813e4075e0747b1d706391fb2c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/google-cloud","events":[{"introduced":"e0e7d6ee03173f3e3ff75e584c675ab81f449f28"},{"fixed":"651bacaa5f5fd7813e4075e0747b1d706391fb2c"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0-beta.1"},{"fixed":"2.2.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["2.2.0","2.1.0","2.0.0","2.0.0-beta.2","2.0.0-beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32266.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:U"}]}