Skip to content
Google CloudCVE-2026-19486

Google Cloud Gemini Enterprise: server-side request forgery

High8.7CVE-2026-19486 · Published Sep 11, 2026

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
Gemini Enterprise Agent Platform App Builder
Product
>= 2025-10-11, < 2026-06-012026-06-01
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Gemini Enterprise Agent Platform SDK: remote code execution
High7.7Sep 15
Google Cloud Gemini CLI: code execution
High7.7Sep 10
Google Cloud Agent Development Kit (ADK) for Python: code injection
Critical10.0Sep 9
Google Cloud Agent Development Kit (ADK): path traversal
High8.7Sep 4
Google Cloud Integration Connectors: missing authorization
High8.5Sep 4
Google Cloud Build: improper authorization
Critical9.4Aug 31

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.