PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19486 Google Cloud CVE debrief

A Server-Side Request Forgery (SSRF) vulnerability exists in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform. This allows an unauthenticated attacker to leak the Compute Engine default service account access token. The vulnerability was patched on June 1, 2026, and users will need to redeploy their previously deployed apps.

Vendor
Google Cloud
Product
Gemini Enterprise Agent Platform App Builder
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for Google Cloud Gemini Enterprise Agent Platform App Builder deployments should assess exposure and apply the patch to prevent potential SSRF attacks. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure, apply patches, and redeploy affected applications. Security teams should also review compensating controls for exposed systems and monitor for potential SS

Why it matters

Defenders should care about CVE-2026-19486 because it allows an unauthenticated attacker to leak the Compute Engine default service account access token, potentially leading to unauthorized access to Compute Engine resources. Gemini Enterprise Agent Platform App Builder deployments prior to June 1, 2026, are affected, and redeployment of previously deployed apps is required after patching.

  • Potential leakage of Compute Engine default service account access token
  • Possible unauthorized access to Compute Engine resources
  • Need to redeploy previously deployed apps after patching
  • Verification of Gemini Enterprise Agent Platform App Builder deployments for exposure

Technical summary

The SSRF vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder allows an unauthenticated attacker to leak the Compute Engine default service account access token. The vulnerability was patched on June 1, 2026. Affected product deployments prior to June 1, 2026, require redeployment after patching. Defenders should prioritize verifying exposure of Gemini Enterprise Agent Platform App Builder deployments and apply the patch to prevent potential SSRF attacks. The vulnerability affects Google Cloud Platform and allows unauthorized access to Compute Engine resources.

Defensive priority

Defenders should prioritize verifying exposure of Gemini Enterprise Agent Platform App Builder deployments and apply the patch to prevent potential SSRF attacks.

Recommended defensive actions

  • Verify Gemini Enterprise Agent Platform App Builder deployments for exposure
  • Apply the patch released on June 1, 2026
  • Redeploy previously deployed apps
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the SSRF vulnerability, its impact, and the patch release date. The vulnerability affects Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01. Defenders should verify exposure and apply the patch to prevent potential SSRF attacks. The patch was released on June 1, 2026, and users will need to redeploy their previously deployed apps. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19486 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19486

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19486 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19486

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes

    f45cbf4e-4146-4068-b7e1-655ffc2c548c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.