CVE-2026-19486
SSRF in Gemini Enterprise Agent Platform App Builder
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
| CWE | CWE-918 |
| Vendor | google cloud |
| Product | gemini enterprise agent platform app builder |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud gemini enterprise agent platform app builder
Be the first to know when new unknown vulnerabilities affecting google cloud gemini enterprise agent platform app builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Gemini Enterprise Agent Platform App Builder
2025-10-11 < 2026-06-01
References
Credits
๐ lambdasawa (Tsubasa Irisawa)