Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.

For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Published: 2026-05-26
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the SetIntegrationRequest policy of Google Cloud Apigee permits attackers to execute server‑side requests and to harvest service account access tokens. The vulnerability is a classic instance of CWE‑918, allowing an attacker to provoke the Apigee runtime to reach internal or external destinations that it otherwise could not. The result is the compromise of authentication credentials, potentially exposing sensitive data or enabling further internal attacks.

Affected Systems

The issue surfaces in Google Cloud Apigee‑X, specifically within the Google Cloud‑managed version and the Hybrid deployment model. For the Google Cloud‑managed Apigee, the vulnerability was fixed in release 1‑16‑0‑apigee‑5 and no action is required for customers already on or above that version. In contrast, Hybrid customers must upgrade to one of the security patch releases: 1.14.4 for the 1.14 platform, 1.15.2 for 1.15, or 1.16.1 for 1.16.

Risk and Exploitability

The CVSS score of 9.2 classifies this flaw as critical, and while the EPSS score is unavailable, the high base score and the potential to expose credentials highlight a significant threat. It does not appear in the CISA KEV catalog, but its severity warrants immediate attention. Exploitation requires an administrator to establish an insecure configuration of the API proxy, meaning the attack vector is likely internal with privileged access or a configuration error. Once this condition is met, the attacker can send crafted requests that reach arbitrary network destinations and pull back authentication tokens, with no additional groundwork beyond the misconfiguration.

Generated by OpenCVE AI on May 26, 2026 at 18:51 UTC.

Remediation

Vendor Solution

For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release  1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 . For Apigee Hybrid: you must upgrade to one of the following security patch releases: * for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1


OpenCVE Recommended Actions

  • For Hybrid deployments, upgrade to the appropriate security patch release: 1.14.4 for 1.14, 1.15.2 for 1.15, or 1.16.1 for 1.16.
  • After upgrading, review the SetIntegrationRequest policy configuration to ensure it does not allow insecure destinations or forwarded requests; disable or remove the policy if it is unnecessary.
  • For customers using the Google Cloud‑managed Apigee, confirm that they are running release 1‑16‑0‑apigee‑5 or later; no further action is required.
  • Monitor Apigee logs for unusual outbound requests and repeated access token requests to detect potential exploitation attempts.

Generated by OpenCVE AI on May 26, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Apigee-x
Vendors & Products Google
Google cloud Apigee-x

Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Title Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber'}


Subscriptions

Google Cloud Apigee-x
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-05-26T19:20:49.023Z

Reserved: 2026-02-09T19:20:21.637Z

Link: CVE-2026-2264

cve-icon Vulnrichment

Updated: 2026-05-26T19:20:24.202Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-26T17:16:30.760

Modified: 2026-05-26T20:26:21.620

Link: CVE-2026-2264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T19:00:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)