Incorrect Authorization Vulnerability in Google Cloud Application Integration
CVE-2026-19759

9.4CRITICAL

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-19759?

A vulnerability exists in the task configuration of Google Cloud Application Integration that permits an authenticated user to execute arbitrary internal RPCs within Google's production network. This issue arises from incorrect authorization measures that allow a privileged identity to leverage an internal-only task type. The vulnerability was addressed on June 17, 2026, and users are not required to take any actions as the patch has been implemented.

Affected Version(s)

Application Integration 0 < 2026-06-17

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gal Doron
.