CVE-2026-81867
Received Received - Intake

Deserialization of Untrusted Data in Google Cloud Application Integration

Vulnerability report for CVE-2026-81867, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GoogleCloud

Description

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
google cloud_application_integration to 2026-06-28 (exc)
google cloud_application_integration From 2025-01-01 (inc)
google cloud_application_integration to 2026-03-30 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Deserialization of Untrusted Data issue in Google Cloud Application Integration's JavaScript Task. It allows an authenticated user with standard permissions to execute arbitrary code on shared production servers by using a specially crafted script that bypasses parameter guards.

Detection Guidance

Detection requires checking if your Google Cloud Application Integration version is prior to 2026-06-28. Use the Google Cloud Console or CLI to verify the installed version. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to run malicious code on shared production servers, potentially leading to unauthorized access, data breaches, or service disruption. However, the vulnerability was patched on 2026-06-28 and no customer action is required.

Compliance Impact

The vulnerability allows arbitrary code execution on shared production servers, which could lead to unauthorized data access or manipulation. This may impact compliance with GDPR (data protection) and HIPAA (health data security) by potentially exposing sensitive data or violating confidentiality requirements.

Mitigation Strategies

No action is required as this vulnerability was patched on 28 June 2026 and no customer action is needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81867. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart