Description
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.


This vulnerability was patched on 24 June 2026, and no customer action is needed.
Published: 2026-08-31
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: No Action Needed
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw in the GitHub Trigger Comment Control feature of Google Cloud Build. It enables an attacker to inject or execute unreviewed code within the build environment by suppressing webhooks. The compromised build process could allow malicious code to run with the permissions of the build service, potentially leading to full system compromise.

Affected Systems

The affected product is Google Cloud Build on the Google Cloud Platform, specifically versions deployed prior to 24 June 2026. Any build environment using a pre‑patch version of Cloud Build is susceptible; post‑patch deployments are not affected.

Risk and Exploitability

With a CVSS score of 9.4, this vulnerability is classified as critical. Although EPSS data is not available, the lack of a KEV listing implies no current known exploitation. The attack vector is likely remote, via a malicious or compromised GitHub repository that can trigger suppressed webhooks, making this risk significant for organizations still running affected Cloud Build instances.

Generated by OpenCVE AI on August 31, 2026 at 09:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • No action required; the vulnerability has been patched.
  • Maintain continuous monitoring of build logs for unauthorized code execution or anomalies to detect potential exploitation earlier.
  • Stay informed about future security updates from Google Cloud by reviewing vendor advisories regularly.

Generated by OpenCVE AI on August 31, 2026 at 09:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud cloud Build
Vendors & Products Google Cloud
Google Cloud cloud Build

Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.
Title Google Cloud Build Comment Control Bypass via Webhook Suppression
Weaknesses CWE-345
CWE-367
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

Google Cloud Cloud Build
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-08-31T11:18:20.587Z

Reserved: 2026-08-10T09:07:34.906Z

Link: CVE-2026-19410

cve-icon Vulnrichment

Updated: 2026-08-31T11:18:17.016Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-31T09:17:03.130

Modified: 2026-08-31T18:50:00.053

Link: CVE-2026-19410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:15:05Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition