GCP-2026-066
Cybersecurity Classified by Officially
Published: 2026-09-28
Description
Description Severity NotesA Confused Deputy vulnerability was discovered in the Email Task component in Application Integration versions prior to June 30, 2026.
What should I do?
No customer action is required. This vulnerability was patched on June 30, 2026.
What vulnerabilities are being addressed?
An authenticated attacker could read and exfiltrate arbitrary Google-internal files using a crafted attachment path.
HighThis is an extract. The publication continues at the source.
Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-066
Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Google — imported from official source
- Official source
- https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
- Imported
- September 28, 2026 11:00
- Versions
- 1 recorded
- Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-066