cbcvebase.

Google Cloud Application Integration vulnerabilities

5 known vulnerabilities affecting google_cloud/application_integration.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-81867P2CRITICALCVSS 9.4fixed in 2026-06-282026-09-28
CVE-2026-81867 [CRITICAL] CWE-502 CVE-2026-81867: A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerab
nvd
CVE-2026-19759P3CRITICALCVSS 9.4fixed in 2026-06-172026-09-28
CVE-2026-19759 [CRITICAL] CWE-863 CVE-2026-19759: An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integ An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type. This vu
nvd
CVE-2025-0982P3CRITICALCVSS 10.0v02025-02-06
CVE-2025-0982 [CRITICAL] CWE-829 CVE-2025-0982: Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an acto Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed.
nvd
CVE-2026-12710P3CRITICALCVSS 9.3≥ 2025-04-28, < 2026-04-042026-08-22
CVE-2026-12710 [CRITICAL] CWE-862 CVE-2026-12710: A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.
nvd
CVE-2026-81375P3HIGHCVSS 8.3fixed in 2026-06-302026-09-28
CVE-2026-81375 [HIGH] CWE-610 CVE-2026-81375: A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration v A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is
nvd