CVE-2026-19486
Last modified
CVE-2026-19486 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Google Cloud | Gemini Enterprise Agent Platform App Builder | >= 2025-10-11, < 2026-06-01 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-19486?
How severe is CVE-2026-19486?
How do I fix CVE-2026-19486?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1948The NEX-Forms – Ultimate Forms Plugin for WordPress plugin f…4.3
- CVE-2026-19480CAI Content Credentials is affected by an Improper Input Val…7.5
- CVE-2026-19481@fastify/busboy is a multipart form-data parser. In versions…7.5
- CVE-2026-19483IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 throu…5.5
- CVE-2026-19484@fastify/busboy is a multipart form-data parser. In versions…7.5
- CVE-2026-19485A Predictable Resource Name vulnerability in BigQuery Import…9.3
- CVE-2026-19487Perl versions from 5.9.4 before 5.41.9 produce incorrect reg…5.3
- CVE-2026-19489Vulnerability in NetScaler ADC and NetScaler Gateway. This …8.8
- CVE-2026-1949Delta Electronics AS320T has incorrect calculation of the bu…9.8
- CVE-2026-19490Vulnerability in NetScaler ADC and NetScaler Gateway. This …9.8
- CVE-2026-19492IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.0…3.2
- CVE-2026-19499Calling strfmon and strfmon_l in the GNU C Library version 2…7.7
Are you affected by CVE-2026-19486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
