Junglewise Threat Intelligence

CVE-2026-19486: Google Cloud Gemini Enterprise Agent Platform App Builder server-side request forgery

CVE-2026-19486 · Severity: info · Published 2026-09-11

Vendors: Google.

Executive brief

Google Cloud Gemini Enterprise Agent Platform App Builder is a platform for building AI-powered applications on Google Cloud Platform. An unauthenticated attacker can exploit an SSRF vulnerability to steal the Compute Engine default service account access token, which provides broad permissions to cloud resources and data.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01. An unauthenticated remote attacker can leverage this to make the application fetch arbitrary internal resources and leak the Compute Engine default service account access token, granting access to cloud infrastructure and services. The flaw affects the App Builder component and is reachable over the network without authentication. Affected deployments must be redeployed after applying the patch released on 2026-06-01.

Affected products

  • Google Cloud Gemini Enterprise Agent Platform App Builder prior to 2026-06-01

Timeline

  • 2026-09-11: disclosed
  • 2026-06-01: patched

References