2026 Fiverr — Cloudinary misconfiguration; private files indexed (Apr disclosure)
Data compromised
User-uploaded documents and media in messaging workflows (varies)
Technical writeup
April 2026 security reporting described sensitive freelancer–client artifacts stored via Cloudinary being reachable through long-lived public URLs without authentication, with many assets discoverable via search-engine indexing. Researchers publicly argued the exposure included tax, ID, contract, and credential-bearing materials for some users. Fiverr was framed as misconfiguration and media-handling policy rather than a SQL database dump; counts of affected users were not standardized across outlets.
Root cause
Misconfigured public media URLs / missing signed-URL controls (per researchers)