๐Ÿ” CVE Alert

CVE-2026-19486

UNKNOWN 0.0

SSRF in Gemini Enterprise Agent Platform App Builder

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.

CWE CWE-918
Vendor google cloud
Product gemini enterprise agent platform app builder
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud gemini enterprise agent platform app builder

Be the first to know when new unknown vulnerabilities affecting google cloud gemini enterprise agent platform app builder are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Gemini Enterprise Agent Platform App Builder
2025-10-11 < 2026-06-01

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes#July_20_2026

Credits

๐Ÿ” lambdasawa (Tsubasa Irisawa)