Incorrect Authorization Flaw in Google Cloud Build by Google
CVE-2026-19410

9.4CRITICAL

Key Information:

Vendor
CVE Published:
31 August 2026

What is CVE-2026-19410?

An Incorrect Authorization vulnerability exists in the GitHub Trigger Comment Control within Google Cloud Build. This flaw allows remote attackers to execute unreviewed code in the build environment by leveraging webhook suppression. Mitigation has been implemented, and users are advised that no action is required on their part, as the vulnerability was patched on June 24, 2026.

Affected Version(s)

Google Cloud Build 0 < 2026-06-24

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

inspector-ambitious
.