PatchSiren cyber security CVE debrief
CVE-2026-2264 Google Cloud CVE debrief
A critical vulnerability in Google Cloud Apigee's SetIntegrationRequest policy enables Server-Side Request Forgery (SSRF) with service account token exfiltration. The flaw requires an administrator to first configure an API proxy insecurely, creating an attack path for remote adversaries to leverage the misconfigured policy for unauthorized internal requests and credential theft. The CVSS 4.0 vector indicates network attack vector, low attack complexity, and high impacts across confidentiality, integrity, and availability dimensions.
- Vendor
- Google Cloud
- Product
- Apigee-X
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations operating Google Cloud Apigee API management platforms, particularly those with custom proxy configurations using SetIntegrationRequest policies. Cloud security teams, API gateway administrators, and DevSecOps engineers responsible for Apigee deployment security.
Technical summary
The SetIntegrationRequest policy in Google Cloud Apigee contains an SSRF vulnerability that allows attackers to direct the proxy to make requests to arbitrary URLs, including internal metadata endpoints. When combined with insecure API proxy configurations, this enables extraction of service account credentials accessible to the Apigee runtime. The attack requires no user interaction and can be executed remotely against vulnerable proxy deployments.
Defensive priority
critical
Recommended defensive actions
- Review all Apigee API proxy configurations for SetIntegrationRequest policy implementations
- Audit API proxies for unauthorized external URL references in integration targets
- Implement strict egress filtering on Apigee runtime environments
- Monitor service account token usage for anomalous access patterns
- Apply Google Cloud security bulletin GCP-2026-034 guidance when available
- Validate that SetIntegrationRequest policies use only approved, internal integration endpoints
Evidence notes
Official Google Cloud security bulletin confirms vulnerability in Apigee SetIntegrationRequest policy. CWE-918 (Server-Side Request Forgery) classification from NVD. CVSS 4.0 scoring applied. Vendor attribution derived from reference domain analysis with low confidence flag requiring review.
Official resources
-
CVE-2026-2264 CVE record
CVE.org
-
CVE-2026-2264 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
f45cbf4e-4146-4068-b7e1-655ffc2c548c
2026-05-26