Exposure of Sensitive Data in Azure Blob Storage Integration for Craft CMS
CVE-2026-32268
8.7HIGH
What is CVE-2026-32268?
The Azure Blob Storage plugin for Craft CMS has a vulnerability that allows unauthenticated users to access bucket names associated with the plugin. This is facilitated through the DefaultController->actionLoadContainerData() endpoint, which permits the use of a valid CSRF token. Such exposure not only reveals available buckets but may also provide sensitive data through error messages returned by Azure. To safeguard against potential attacks, it is recommended that users upgrade to version 2.1.1 of the plugin.
Affected Version(s)
azure-blob >= 2.0.0-beta.1, < 2.1.1
