🔐 CVE Alert

CVE-2026-19759

UNKNOWN 0.0

Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type. This vulnerability was patched on 17 June 2026, and no customer action is needed.

CWE CWE-863
Vendor google cloud
Product application integration
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud application integration

Be the first to know when new unknown vulnerabilities affecting google cloud application integration are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Google Cloud / Application Integration
0 < 2026-06-17

References

NVD ↗ CVE.org ↗ EPSS Data ↗
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-064 docs.cloud.google.com: https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-064

Credits

🔍 Gal Doron