A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token.



This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Users will need to redeploy their previously deployed apps.


Workaround

No workaround given by the vendor.

History

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Title SSRF in Gemini Enterprise Agent Platform App Builder
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-11T08:18:25.964Z

Reserved: 2026-08-10T16:22:21.240Z

Link: CVE-2026-19486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T09:17:20.327

Modified: 2026-09-11T09:17:20.327

Link: CVE-2026-19486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses