← volver
CVE-2026-8934

Cross-Project Information Leakage in Google App Engine UI

CVSS 6.9 MEDIUMEPSS 0.4%CWE-862
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and no customer action is needed.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/U:Clear

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →