CVE Database
/

CVE-2026-32266

Back to search

CVE-2026-32266

Published: Mar 18, 2026

Modified: Mar 18, 2026

PUBLISHED

Description

The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.

VendorProductVersions

craftcms

google-cloud

affected
>= 2.0.0-beta.1, < 2.2.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now