PT-2026-25817 · Packagist · Craftcms/Aws-S3

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-32265

CVSS v4.0
6.9
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Unauthenticated users can view a list of buckets the plugin has access to.
The
BucketsController->actionLoadBucketData()
endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see.
Users should update to version 2.2.5 of the plugin to mitigate the issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-32265
GHSA-HWJ7-4VGC-J3V9

Affected Products

Craftcms/Aws-S3