GCP-2026-064Critical
GCP-2026-064 — Published: 2026-09-28Description Description Severity Notes An Incorrect Authorization vulnerability was discovered in the…
🔗 CVE IDs covered (1)
📋 Description
Published: 2026-09-28Description Description Severity Notes An Incorrect Authorization vulnerability was discovered in the task configuration in Application Integration versions prior to June 17, 2026. What should I do? No customer action is required. This vulnerability was patched on June 17, 2026. What vulnerabilities are being addressed? An authenticated user could use an internal-only task type to execute arbitrary internal RPCs from the Google-internal production network under a privileged identity. Critical CVE-2026-19759