Executive brief
A Confused Deputy vulnerability was discovered in the Email Task component of Google Cloud Application Integration, allowing authenticated attackers to read and exfiltrate arbitrary internal Google files using crafted attachment paths. This could lead to exposure of sensitive Google-internal data. The vulnerability was patched on June 30, 2026, and no customer action is required as the fix has been deployed.
Technical details
The vulnerability is a Confused Deputy flaw in Application Integration's Email Task component that allows an authenticated attacker to bypass authorization checks and access Google-internal files through a crafted attachment path parameter. The attack requires authentication but does not require user interaction. An attacker could exfiltrate arbitrary sensitive internal files, and a patch was released on June 30, 2026.
Affected products
- Google Cloud Application Integration prior to June 30, 2026
Timeline
- 2026-06-30: patched
- 2026-09-28: disclosed