{"id":"CVE-2026-32266","aliases":["GHSA-67cr-jmh8-4jpq"],"url":"https://o3.security/vulnerability/CVE-2026-32266","summary":"Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability","details":"The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.","published":"2026-03-18T03:46:00.150Z","modified":"2026-08-12T03:51:12.223421946Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/google-cloud","fixedVersion":"2.2.1"}],"fix":{"url":"https://github.com/craftcms/google-cloud/commit/651bacaa5f5fd7813e4075e0747b1d706391fb2c","label":"craftcms/google-cloud@651baca"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32266.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/google-cloud/security/advisories/GHSA-67cr-jmh8-4jpq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32266"},{"type":"FIX","url":"https://github.com/craftcms/google-cloud/commit/651bacaa5f5fd7813e4075e0747b1d706391fb2c"},{"type":"PACKAGE","url":"https://github.com/craftcms/google-cloud"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.223421946Z"}}