๐Ÿ” CVE Alert

CVE-2026-81867

UNKNOWN 0.0

Deserialization of Untrusted Data in Application Integration allows Remote Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.

CWE CWE-502
Vendor google cloud
Product application integration
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud application integration

Be the first to know when new unknown vulnerabilities affecting google cloud application integration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Application Integration
0 < 2026-06-28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-065 docs.cloud.google.com: https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-065

Credits

๐Ÿ” Brahim Nah