CVE-2026-19410: Google Cloud Build Comment Control Bypass via Webhook Suppression
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.
This vulnerability was patched on 24 June 2026, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
Which Cloud Build workflows were exposed to this issue?
The issue affected GitHub Trigger Comment Control in Google Cloud Build before 24 June 2026. Workflows not using that trigger comment-control functionality are not identified as affected by the provided information.
What access does an attacker need to exploit it?
The vulnerability is described as remotely exploitable through webhook suppression. Successful exploitation could allow execution of unreviewed code in the build environment; no additional attacker prerequisites are provided.
Do customers need to patch or change their Cloud Build configuration?
No customer action is needed. Google Cloud Build patched the issue on 24 June 2026.