Executive brief
Google Cloud Application Integration is a service for building enterprise integration workflows. A missing authorization vulnerability in the QueryEngineTask component allowed external attackers to access sensitive internal data without proper permission checks. The vulnerability was patched on April 4, 2026, and no customer action is required.
Technical details
This is a missing authorization (CWE-862) vulnerability in the QueryEngineTask component of Google Cloud Application Integration affecting versions released between April 28, 2025 and April 4, 2026. The vulnerable component fails to properly validate that an external caller has authorization to execute query operations, allowing unauthenticated or unauthorized access to internal data. The attack vector is network-based with no authentication required. Google patched this issue on April 4, 2026, and the patch was rolled out transparently without requiring customer action.
Affected products
- Google Cloud Application Integration 2025-04-28 to 2026-04-04
Timeline
- 2026-04-04: patched: Vulnerability patched; no customer action required
- 2026-08-21: disclosed: Security advisory published in release notes
- 2026-08-22: advisory: Published to NVD