Description
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token.



This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Published: 2026-09-11
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Server‑Side Request Forgery that leaks a Compute Engine default service account access token
Action: Redeploy Apps
AI Analysis

Impact

A Server‑Side Request Forgery flaw in the Gemini Enterprise Agent Platform App Builder allows an attacker without authentication to direct the server to internal resources and retrieve the default Compute Engine service account access token. The exposed token can be used to impersonate the service account, potentially leading to unauthorized access or further privilege escalation. The weakness is classified as CWE‑918.

Affected Systems

The vulnerability affects Google Cloud Gemini Enterprise Agent Platform App Builder deployments on Google Cloud Platform that use any version of the app builder released before 2026‑06‑01. Users who have deployed applications with those versions are impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating high severity, and the EPSS score is not available, but the lack of authentication required makes it highly exploitable in practice. The flaw is not listed in the CISA KEV catalog, yet its potential to leak privileged tokens makes it a significant risk. Attackers can exploit the SSRF by targeting internal endpoints, and because it is unauthenticated, the barrier to exploitation is minimal.

Generated by OpenCVE AI on September 11, 2026 at 09:21 UTC.

Remediation

Vendor Solution

Users will need to redeploy their previously deployed apps.


OpenCVE Recommended Actions

  • Redeploy all previously deployed applications to a version of the Gemini Enterprise Agent Platform App Builder released on or after 2026‑06‑01
  • Upgrade the App Builder component to the latest patched release
  • Restrict outbound network traffic from the App Builder environment to limit potential SSRF exploitation until a new version is in place

Generated by OpenCVE AI on September 11, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Title SSRF in Gemini Enterprise Agent Platform App Builder
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-11T08:18:25.964Z

Reserved: 2026-08-10T16:22:21.240Z

Link: CVE-2026-19486

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T09:17:20.327

Modified: 2026-09-11T09:17:20.327

Link: CVE-2026-19486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:30:07Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)