This vulnerability was patched on 30 June 2026, and no customer action is needed.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google application Integration |
|
| Vendors & Products |
Google
Google application Integration |
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed. | |
| Title | Confused Deputy in Application Integration allows Internal File Read | |
| Weaknesses | CWE-610 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-28T13:31:29.289Z
Reserved: 2026-08-26T18:42:15.725Z
Link: CVE-2026-81375
Updated: 2026-09-28T13:24:19.831Z
Status : Received
Published: 2026-09-28T11:16:47.860
Modified: 2026-09-28T14:17:17.653
Link: CVE-2026-81375
No data.
OpenCVE Enrichment
Updated: 2026-09-28T16:15:03Z