Impact
A Server‑Side Request Forgery flaw in the Gemini Enterprise Agent Platform App Builder allows an attacker without authentication to direct the server to internal resources and retrieve the default Compute Engine service account access token. The exposed token can be used to impersonate the service account, potentially leading to unauthorized access or further privilege escalation. The weakness is classified as CWE‑918.
Affected Systems
The vulnerability affects Google Cloud Gemini Enterprise Agent Platform App Builder deployments on Google Cloud Platform that use any version of the app builder released before 2026‑06‑01. Users who have deployed applications with those versions are impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity, and the EPSS score is not available, but the lack of authentication required makes it highly exploitable in practice. The flaw is not listed in the CISA KEV catalog, yet its potential to leak privileged tokens makes it a significant risk. Attackers can exploit the SSRF by targeting internal endpoints, and because it is unauthenticated, the barrier to exploitation is minimal.
OpenCVE Enrichment