rootpwn

critical · CVSS v3 9.8 · CVSS v4 9.4

CVE-2026-81867

Google Cloud Application Integration's JavaScript Task had a deserialization flaw that allowed authenticated users to execute arbitrary code

Overview

Google Cloud Application Integration's JavaScript Task had a deserialization flaw that allowed authenticated users to execute arbitrary code on shared production servers. The issue existed before 28 June 2026 and was fixed in that release. No action required from customers.

Description

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.

Impact

Confidentiality, integrity, and availability of shared production servers were at risk. Authenticated users with standard permissions could run arbitrary code, potentially exfiltrate data, modify services, or disrupt availability. Defenders should monitor for anomalous activity on GCP Application Integration instances.

Remediation

Patch applied on 28 June 2026; no customer action needed. Ensure your GCP Application Integration instances are running the latest version (>=2026-06-28). Verify that no older versions are deployed and that access controls restrict authenticated users to least privilege.

Risk context

Critical severity with CVSS 9.8 indicates high risk; however, the vulnerability has been patched and no customer action is required.

Affected products

  • Google Cloud Platform
  • Google Cloud Application Integration
  • GCP JavaScript Task

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
9.4
EPSS
—

deserialization gcp critical application-integration authenticated patch shared-servers

← All CVEs