Home

Description

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

PUBLISHED Reserved 2026-02-05 | Published 2026-05-15 | Updated 2026-05-15 | Assigner GoogleCloud




CRITICAL: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

Problem types

CWE-862 Missing Authorization

Product status

Default status
unaffected

Any version before 2026-01-23
affected

Credits

Arvin Shivram reporter

References

docs.cloud.google.com/gemini/enterprise/docs/release-notes

cve.org (CVE-2026-2031)

nvd.nist.gov (CVE-2026-2031)

Download JSON