CVE-2026-19410
largeIncorrect Authorization in Google Cloud Build GitHub triggers runs unreviewed code
CVE-2026-19410 is an incorrect authorization flaw (CWE-345, CWE-367) in the GitHub trigger comment control feature of Google Cloud Build, Google's managed CI/CD service on Google Cloud Platform. By manipulating or suppressing the webhook activity that normally gates a build on an authorized pull-request comment — a race-condition-style bypass — a remote attacker can cause Cloud Build to run without the required review authorization. Successful exploitation lets unreviewed, potentially attacker-controlled code execute in the customer's build environment, where it can access build secrets, source code, and credentials, with high impact on confidentiality, integrity, and availability (CVSS 4.0 score 9.4, critical). Only Google Cloud Build customers using GitHub triggers — specifically the trigger comment control feature — are affected; because Cloud Build is a managed service, Google patched it server-side on 24 June 2026 and states no customer action is needed. There is no known public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.2%, 10th percentile), indicating no known exploitation to date.
What to do: No upgrade or configuration change is required, as Google patched the flaw server-side on 24 June 2026. As a precaution, review Cloud Build audit logs for pull-request-triggered builds lacking the expected review comments prior to that date, and confirm GitHub triggers run with least-privilege build service accounts and tightly scoped secrets to limit impact if unreviewed code ran.
| Google Cloud Build (GitHub trigger comment control) | prior to 2026-06-24 (managed service; fixed server-side on 24 June 2026) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.
- Weakness
- CWE-345, CWE-367
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
In the news0 stories
No ingested article mentions this CVE yet.