GCP-2026-064Critical

GCP-2026-064 — Published: 2026-09-28Description Description Severity Notes An Incorrect Authorization vulnerability was discovered in the…

Published
September 28, 2026
Last Modified
September 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Published: 2026-09-28Description Description Severity Notes An Incorrect Authorization vulnerability was discovered in the task configuration in Application Integration versions prior to June 17, 2026. What should I do? No customer action is required. This vulnerability was patched on June 17, 2026. What vulnerabilities are being addressed? An authenticated user could use an internal-only task type to execute arbitrary internal RPCs from the Google-internal production network under a privileged identity. Critical CVE-2026-19759

🔗 References (1)