CVE-2026-2244 HIGH

CVE-2026-2244: Sensitive Data Exposure in Google Cloud Vertex AI Workbench

Vendor Google Cloud
Product Vertex AI Workbench
Weakness CWE-200 · Info exposure
Published February 26, 2026
Last update February 26, 2026

CVSS base score

8.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear

What the vulnerability does

01Description

A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.

Key dates

02Disclosure timeline

February 26, 2026 CVE published
February 26, 2026 Record updated