HarborGuard / CVE
Back to search
CRITICALCVE-2026-2031Published Modified CNA GoogleCloud

CVE-2026-2031: Google Cloud Application Integration: Exposed internal APIs allow Information Disclosure and Remote Code Execution.

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

Metrics

CVSS v4.0
10.0
Severity
CRITICAL
Fixed in
2026-01-23
Affected Products
1

Fix available

2026-01-23
Affected packages
  • Google Cloud / Internal Integration Platform APIs
    < 2026-01-23 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear