Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19759— Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution

Quick assessment

Affected
Google Cloud Application Integration
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Google Cloud Application Integration(2026年6月17日之前的版本)中存在的任务配置“不正确授权”漏洞,允许经过身份验证的 Google Cloud 用户使用仅限内部的任务类型,从 Google 生产网络内部以特权身份执行任意内部远程过程调用(RPC)。 该漏洞已于2026年6月17日修复,用户无需采取任何操作。

CVSS 9.4 · Critical

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19759

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution
Source: CVE Program / CVE List V5
Vulnerability Description
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type. This vulnerability was patched on 17 June 2026, and no customer action is needed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Google Cloud Application Integration 0 ~ 2026-06-17 -

II. Public POCs for CVE-2026-19759

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19759

请登录查看更多情报信息。

Other References for CVE-2026-19759 (2)

Same Patch Batch · Google Cloud · 2026-09-28 · 3 CVEs total

CVE-2026-81867 9.4 CRITICAL Deserialization of Untrusted Data in Application Integration allows Remote Code Execution
CVE-2026-81375 8.3 HIGH Confused Deputy in Application Integration allows Internal File Read

IV. Related Vulnerabilities

V. Comments for CVE-2026-19759

No comments yet


Leave a comment