high · CVSS v3 6.5 · CVSS v4 8.3
CVE-2026-81375
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 202…
Description
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed.
Scores
- Severity
- high
- CVSS v2
- 4
- CVSS v3
- 6.5
- CVSS v4
- 8.3
- EPSS
- —