ZeroHour

CVE-2026-19486

moderate

Unauthenticated SSRF in Google Cloud Gemini Enterprise Agent Platform App Builder

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Google Cloud's Gemini Enterprise Agent Platform App Builder contains a server-side request forgery (SSRF, CWE-918) in versions prior to 2026-06-01, exploitable by unauthenticated attackers with network access to an affected deployment. Because the flaw requires no authentication, privileges, or user interaction, an attacker can induce server-side requests and retrieve the Compute Engine default service account access token. With that token, the attacker can call Google Cloud APIs with whatever permissions the Compute Engine default service account holds, driving the high confidentiality impact reflected in the 8.7 CVSS 4.0 score. Any organization running apps deployed via App Builder on Google Cloud Platform before the 1 June 2026 fix is affected, and customers must redeploy their previously deployed apps to pick up the remediation. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time.

What to do: Redeploy all previously deployed App Builder apps on the patched platform (fix dated 1 June 2026), since patching alone does not update already-deployed apps. Review Cloud Audit Logs for unexpected issuance or use of the Compute Engine default service account access token and audit the IAM permissions and OAuth scopes attached to the default service account. Until redeployment is complete, restrict network access to affected apps to trusted networks.

Affected
Google Gemini Enterprise Agent Platform App Builder (Google Cloud Platform)all versions prior to 2026-06-01
Estimated exposure
moderateplausibly on the order of 1,000–10,000 deployed apps across enterprise tenants (order-of-magnitude estimate; no public counts) — No public install or internet-exposure counts exist for this recently launched, enterprise-only Google Cloud platform, so the estimate assumes typical per-organization adoption of enterprise agent-building tools (thousands of tenants/apps)…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.

Weakness
CWE-918
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

In the news

No ingested article mentions this CVE yet.