Deserialization of Untrusted Data in Application Integration allows Remote Code Execution
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.4
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.
This vulnerability was patched on 28 June 2026, and no customer action is needed.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear
Productos afectados
Google Cloud · Application Integration