๐Ÿ” CVE Alert

CVE-2026-81375

UNKNOWN 0.0

Confused Deputy in Application Integration allows Internal File Read

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed.

CWE CWE-610
Vendor google cloud
Product application integration
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud application integration

Be the first to know when new unknown vulnerabilities affecting google cloud application integration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Application Integration
0 < 2026-06-30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-066 docs.cloud.google.com: https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-066

Credits

๐Ÿ” Guillaume Berleur