PatchSiren cyber security CVE debrief
CVE-2026-19486 Google Cloud CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability exists in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform. This allows an unauthenticated attacker to leak the Compute Engine default service account access token. The vulnerability was patched on June 1, 2026, and users will need to redeploy their previously deployed apps.
- Vendor
- Google Cloud
- Product
- Gemini Enterprise Agent Platform App Builder
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for Google Cloud Gemini Enterprise Agent Platform App Builder deployments should assess exposure and apply the patch to prevent potential SSRF attacks. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify exposure, apply patches, and redeploy affected applications. Security teams should also review compensating controls for exposed systems and monitor for potential SS
Why it matters
Defenders should care about CVE-2026-19486 because it allows an unauthenticated attacker to leak the Compute Engine default service account access token, potentially leading to unauthorized access to Compute Engine resources. Gemini Enterprise Agent Platform App Builder deployments prior to June 1, 2026, are affected, and redeployment of previously deployed apps is required after patching.
- Potential leakage of Compute Engine default service account access token
- Possible unauthorized access to Compute Engine resources
- Need to redeploy previously deployed apps after patching
- Verification of Gemini Enterprise Agent Platform App Builder deployments for exposure
Technical summary
The SSRF vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder allows an unauthenticated attacker to leak the Compute Engine default service account access token. The vulnerability was patched on June 1, 2026. Affected product deployments prior to June 1, 2026, require redeployment after patching. Defenders should prioritize verifying exposure of Gemini Enterprise Agent Platform App Builder deployments and apply the patch to prevent potential SSRF attacks. The vulnerability affects Google Cloud Platform and allows unauthorized access to Compute Engine resources.
Defensive priority
Defenders should prioritize verifying exposure of Gemini Enterprise Agent Platform App Builder deployments and apply the patch to prevent potential SSRF attacks.
Recommended defensive actions
- Verify Gemini Enterprise Agent Platform App Builder deployments for exposure
- Apply the patch released on June 1, 2026
- Redeploy previously deployed apps
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the SSRF vulnerability, its impact, and the patch release date. The vulnerability affects Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01. Defenders should verify exposure and apply the patch to prevent potential SSRF attacks. The patch was released on June 1, 2026, and users will need to redeploy their previously deployed apps. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impacts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19486 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19486
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19486 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19486
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.cloud.google.com/gemini-enterprise-agent-platform/release-notes
f45cbf4e-4146-4068-b7e1-655ffc2c548c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.