Executive brief
A security vulnerability in Google Cloud Apigee could allow an attacker to trick the system into making unauthorized requests to external servers. This flaw can be used to steal sensitive service account access tokens, which could grant an attacker broader access to cloud resources. The issue specifically affects organizations using the SetIntegrationRequest policy with insecure configurations.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Google Cloud Apigee SetIntegrationRequest policy due to a lack of validation for the IntegrationRegion parameter. If an attacker can control a flow variable used for this parameter, they can redirect requests to an attacker-controlled host. This allows for the exfiltration of service account access tokens associated with the API proxy. Exploitation requires that an administrator has established an insecure configuration of the API proxy where flow variables are externally controllable. Google has patched the issue in Apigee release 1-16-0-apigee-5 and various Apigee Hybrid security patches.
Affected products
- Google Cloud Apigee Prior to 1-16-0-apigee-5
- Google Cloud Apigee Hybrid 1.14.x < 1.14.4, 1.15.x < 1.15.2, 1.16.x < 1.16.1
Timeline
- 2026-05-20: advisory: Google Cloud published security bulletin GCP-2026-034
- 2026-05-26: disclosed: CVE-2026-2264 published to NVD