A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token.



This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Users will need to redeploy their previously deployed apps.


Workaround

No workaround given by the vendor.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Title SSRF in Gemini Enterprise Agent Platform App Builder
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-11T14:27:11.496Z

Reserved: 2026-08-10T16:22:21.240Z

Link: CVE-2026-19486

cve-icon Vulnrichment

Updated: 2026-09-11T14:15:45.707Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T09:17:20.327

Modified: 2026-09-11T15:17:00.623

Link: CVE-2026-19486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses