Description
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path.
This vulnerability was patched on 30 June 2026, and no customer action is needed.
This vulnerability was patched on 30 June 2026, and no customer action is needed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 28 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed. | |
| Title | Confused Deputy in Application Integration allows Internal File Read | |
| Weaknesses | CWE-610 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-28T10:58:46.532Z
Reserved: 2026-08-26T18:42:15.725Z
Link: CVE-2026-81375
No data.
Status : Received
Published: 2026-09-28T11:16:47.860
Modified: 2026-09-28T11:16:47.860
Link: CVE-2026-81375
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-610
Externally Controlled Reference to a Resource in Another Sphere