← Fiverr

2026 Fiverr — Cloudinary misconfiguration; private files indexed (Apr disclosure)

2026 Unknown records affected Share on X

Data compromised

User-uploaded documents and media in messaging workflows (varies)

Technical writeup

April 2026 security reporting described sensitive freelancer–client artifacts stored via Cloudinary being reachable through long-lived public URLs without authentication, with many assets discoverable via search-engine indexing. Researchers publicly argued the exposure included tax, ID, contract, and credential-bearing materials for some users. Fiverr was framed as misconfiguration and media-handling policy rather than a SQL database dump; counts of affected users were not standardized across outlets.

Root cause

Misconfigured public media URLs / missing signed-URL controls (per researchers)

References