Executive brief
An authentication bypass vulnerability in Google Cloud Application Integration allowed authenticated users to execute arbitrary internal operations from Google's production network using elevated privileges. An attacker with any valid account could escalate access to internal systems. Google patched this on June 17, 2026, and no customer action is required.
Technical details
An Incorrect Authorization vulnerability in Application Integration's task configuration allowed authenticated users to invoke internal-only task types and execute arbitrary internal RPCs from the Google-internal production network under a privileged identity. The vulnerability required authentication but no additional user interaction. The flaw was patched on June 17, 2026.
Affected products
- Google Application Integration prior to June 17, 2026
Timeline
- 2026-06-17: patched: Vulnerability patched
- 2026-09-28: disclosed: GCP-2026-064 published