CVE-2026-32265: Amazon S3 for Craft CMS has an Information Disclosure vulnerability
(updated )
Unauthenticated users can view a list of buckets the plugin has access to.
The BucketsController->actionLoadBucketData() endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see.
Users should update to version 2.2.5 of the plugin to mitigate the issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-32265 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →