Unauthorized Access Vulnerability in Amazon S3 Plugin for Craft CMS
CVE-2026-32265
6.9MEDIUM
What is CVE-2026-32265?
The Amazon S3 for Craft CMS plugin has a vulnerability that allows unauthenticated users to view accessible S3 buckets. This vulnerability exists due to improper validation in the BucketsController->actionLoadBucketData() endpoint, enabling attackers with a valid CSRF token to enumerate bucket names. To protect against this exposure, it's recommended to upgrade to version 2.2.5 or later of the plugin.
Affected Version(s)
aws-s3 >= 2.0.2, < 2.2.5
