8.3

CVE-2026-81375

Confused Deputy in Application Integration allows Internal File Read

A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path.


This vulnerability was patched on 30 June 2026, and no customer action is needed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGoogle Cloud
≫
Produkt Application Integration
Default Statusunaffected
Version 0
Version < 2026-06-30
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
f45cbf4e-4146-4068-b7e1-655ffc2c548c 8.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
CWE-610 Externally Controlled Reference to a Resource in Another Sphere

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

https://docs.cloud.google.com/support/bulletins#gcp-2026-066
https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-066