CVE-2026-19410: Google Cloud Build Comment Control Bypass via Webhook Suppression

Published Aug 31, 2026
·
Updated

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.

This vulnerability was patched on 24 June 2026, and no customer action is needed.

Affected Software

1 affected component
Google Cloud Build<2026-06-24

Event History

Aug 31, 2026
CVE Published
via MITRE·08:14 AM
Data Sourced
via MITRE·08:14 AM
DescriptionWeakness

Frequently Asked Questions

1

Which Cloud Build workflows were exposed to this issue?

The issue affected GitHub Trigger Comment Control in Google Cloud Build before 24 June 2026. Workflows not using that trigger comment-control functionality are not identified as affected by the provided information.

2

What access does an attacker need to exploit it?

The vulnerability is described as remotely exploitable through webhook suppression. Successful exploitation could allow execution of unreviewed code in the build environment; no additional attacker prerequisites are provided.

3

Do customers need to patch or change their Cloud Build configuration?

No customer action is needed. Google Cloud Build patched the issue on 24 June 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203