Server-Side Request Forgery in Google Cloud Gemini Enterprise Agent Platform
CVE-2026-19486

8.7HIGH

Key Information:

Vendor
CVE Published:
11 September 2026

What is CVE-2026-19486?

The vulnerability allows an unauthenticated attacker to exploit the Google Cloud Gemini Enterprise Agent Platform, which can lead to the leakage of the Compute Engine default service account access token. This can pose significant security risks as it may allow the attacker to perform unauthorized actions within the Google Cloud environment. Users are advised to redeploy their applications to versions released after the patch on June 1, 2026, to mitigate this issue.

Affected Version(s)

Gemini Enterprise Agent Platform App Builder 2025-10-11 < 2026-06-01

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lambdasawa (Tsubasa Irisawa)
.