Junglewise Threat Intelligence

CVE-2026-8934: Google Cloud Console missing authorization in App Engine GraphQL API

CVE-2026-8934 · Severity: high · CVSS 6.9 · Published 2026-06-22

Technologies: Google Cloud Platform. Vendors: Google.

Executive brief

A security flaw was identified in the Google Cloud Console's App Engine dashboard that could have allowed unauthorized access to sensitive system logs. An attacker could have potentially viewed request logs belonging to other customers' projects, which might contain private data or operational details. Google has already patched this issue on their backend, and no action is required from customers to secure their accounts.

Technical details

A Missing Authorization (CWE-862) vulnerability existed in the 'GetDashboardAppStats' GraphQL private API operation within the Google App Engine section of the Google Cloud Console. The flaw allowed an unauthenticated remote attacker to bypass intended access controls by sending specially crafted GraphQL requests. Successful exploitation enabled the exfiltration of sensitive multi-tenant request logs from projects other than the attacker's own. Google remediated the vulnerability on April 7, 2026, by implementing proper authorization checks on the affected API endpoint.

Affected products

  • Google Cloud Cloud Console UIs Before 2026-04-07

Timeline

  • 2026-04-07: patched: Vulnerability was patched by Google; no customer action required.
  • 2026-06-22: disclosed: Initial advisory publication.

References

Related threats