CVE-2026-19486
8.7Google · Gemini Enterprise Agent Platform App Builder
A Server-Side Request Forgery vulnerability in the Google Gemini Enterprise Agent Platform App Builder allows unauthenticated attackers to leak Compute Engine default service account access tokens.
Executive summary
A critical Server-Side Request Forgery vulnerability in the Google Gemini Enterprise Agent Platform App Builder enables unauthenticated attackers to compromise service account access tokens.
Vulnerability
The application is susceptible to Server-Side Request Forgery (CWE-918) via an unauthenticated endpoint, which permits an attacker to force the server to disclose sensitive Compute Engine default service account access tokens.
Business impact
The compromise of a default service account token provides an attacker with the identity and permissions of that account within the Google Cloud environment. With a CVSS score of 8.7, this high-severity vulnerability could lead to unauthorized data access, lateral movement within the cloud infrastructure, and potential exfiltration of sensitive organizational assets.
Remediation
Immediate Action: Ensure all instances of the Gemini Enterprise Agent Platform App Builder are updated to the 2026-06-01 release or later, and perform a full redeployment of all previously existing applications.
Proactive Monitoring: Review cloud audit logs for anomalous outbound requests originating from the App Builder environment and monitor service account activity for unauthorized access attempts.
Compensating Controls: Implement strict egress filtering and network security policies within the Google Cloud environment to limit the ability of the App Builder service to communicate with sensitive internal metadata endpoints.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the sensitive nature of service account tokens, this vulnerability poses a significant risk to cloud environment integrity. Administrators must prioritize the redeployment of all affected applications as specified by the vendor to neutralize this SSRF vector immediately.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by lambdasawa (Tsubasa Irisawa), per the CVE Program record.