9.4
CVE-2026-81867
- EPSS 0.36%
- Veröffentlicht 28.09.2026 10:49:16
- Zuletzt bearbeitet 30.09.2026 14:17:30
- Erkennungen
Deserialization of Untrusted Data in Application Integration allows Remote Code Execution
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGoogle Cloud
≫
Produkt
Application Integration
Default Statusunaffected
Version
0
Version <
2026-06-28
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.267 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| f45cbf4e-4146-4068-b7e1-655ffc2c548c | 9.4 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://docs.cloud.google.com/support/bulletins#gcp-2026-065
https://docs.cloud.google.com/application-integration/docs/security-bulletins#gcp-2026-065