CVE-2026-2031 CRITICAL

CVE-2026-2031: Google Cloud Application Integration: Exposed internal APIs allow Information Disclosure and Remote Code Execution.

Vendor Google Cloud
Product Internal Integration Platform APIs
Weakness CWE-862 · Missing authorization
Published May 15, 2026
Last update May 15, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

What the vulnerability does

01Description

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

Key dates

02Disclosure timeline

May 15, 2026 CVE published
May 15, 2026 Record updated

Related vulnerabilities

04Related CVE