CVE-2026-81867
Deserialization of Untrusted Data in Application Integration allows Remote Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.
| CWE | CWE-502 |
| Vendor | google cloud |
| Product | application integration |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud application integration
Be the first to know when new unknown vulnerabilities affecting google cloud application integration are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Application Integration
0 < 2026-06-28
References
Credits
๐ Brahim Nah