CVE-2026-2264
Last modified
CVE-2026-2264 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Google Cloud | Apigee-X | < 1.14.4; < 1.15.2; < 1.16.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-2264?
How severe is CVE-2026-2264?
How do I fix CVE-2026-2264?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22634Rejected reason: Not used
- CVE-2026-22635Rejected reason: Not used
- CVE-2026-22636Rejected reason: Not used
- CVE-2026-22637Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22638Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22639Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22640Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22641Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22642Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22643Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-22644Certain requests pass the authentication token in the URL as…7.5
- CVE-2026-22645The application discloses all used components, versions and …5.3
Are you affected by CVE-2026-2264?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
