Skip to content
Google CloudCVE-2026-19410

Google Cloud Build: improper authorization

Critical9.4CVE-2026-19410 · Published Aug 31, 2026

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
Google Cloud Build
Product
< 2026-06-242026-06-24
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-345, CWE-367

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Agent Development Kit (ADK) for Python: code injection
Critical10.0Sep 9
Google Cloud Agent Development Kit (ADK): path traversal
High8.7Sep 4
Google Cloud Integration Connectors: missing authorization
High8.5Sep 4
Google Cloud Vertex AI Search for Commerce: weak randomness
Critical9.3Aug 26
Google Cloud BigQuery Data Transfer Service: improper input validation
Critical9.4Aug 26
Google Cloud Application Integration: missing authorization
Critical9.3Aug 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.