Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.

For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Published: 2026-05-26
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release  1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 . For Apigee Hybrid: you must upgrade to one of the following security patch releases: * for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Apigee-x
Vendors & Products Google
Google cloud Apigee-x

Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Title Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Google Cloud Apigee-x
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-05-26T16:30:45.810Z

Reserved: 2026-02-09T19:20:21.637Z

Link: CVE-2026-2264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-26T17:16:30.760

Modified: 2026-05-26T17:16:30.760

Link: CVE-2026-2264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T18:30:11Z

Weaknesses