critical · CVSS v3 8.8 · CVSS v4 9.4
CVE-2026-19759
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prio…
Description
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type. This vulnerability was patched on 17 June 2026, and no customer action is needed.
Scores
- Severity
- critical
- CVSS v2
- 5.5
- CVSS v3
- 8.8
- CVSS v4
- 9.4
- EPSS
- —