CVE-2026-2031

CRITICAL

Google Cloud Application Integration: Exposed internal APIs allow Information Disclosure and Remote Code Execution.

Title source: cna
STIX 2.1

Description

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

Scores

CVSS v4 10.0
EPSS 0.0049
EPSS Percentile 37.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
Google Cloud/Internal Integration Platform APIs < 2026-01-23
Published May 15, 2026
Tracked Since May 15, 2026