PT-2026-25843 · Packagist · Craftcms/Google-Cloud

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-32266

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Unauthenticated users can view a list of buckets the plugin has access to.
The
DefaultController->actionLoadBucketData()
endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see.
Users should update to version 2.2.1 of the plugin to mitigate the issue.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-32266
GHSA-67CR-JMH8-4JPQ

Affected Products

Craftcms/Google-Cloud