Google CloudCVE-2026-19410
Google Cloud Build: improper authorization
Critical9.4CVE-2026-19410 · Published Aug 31, 2026
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Google Cloud Build Product | < 2026-06-24 | 2026-06-24 |
Details and references
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Google Cloud Agent Development Kit (ADK) for Python: code injection | Critical10.0 | 2.7.0 |
| Sep 4 | Google Cloud Agent Development Kit (ADK): path traversal | High8.7 | 1.22.0 |
| Sep 4 | Google Cloud Integration Connectors: missing authorization | High8.5 | 2025-12-11 |
| Aug 26 | Google Cloud Vertex AI Search for Commerce: weak randomness | Critical9.3 | 2026-04-27 |
| Aug 26 | Google Cloud BigQuery Data Transfer Service: improper input validation | Critical9.4 | 2026-05-01 |
| Aug 22 | Google Cloud Application Integration: missing authorization | Critical9.3 | 2026-04-04 |