CVE-2026-19486: SSRF in Gemini Enterprise Agent Platform App Builder
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token.
This vulnerability was patched on 01 June 2026. Users will need to redeploy their previously deployed apps.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Cloud Gemini Enterprise Agent Platform App Builderto a version that resolves this vulnerability.Fixed in 2026-06-01 - Operational
Redeploy previously deployed apps after the 01 June 2026 patch.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Previously deployed Google Cloud Gemini Enterprise Agent Platform App Builder apps are affected if they were deployed using a version prior to 2026-06-01. The vendor states that these apps need to be redeployed.
Does an attacker need credentials to exploit the vulnerability?
No. The vulnerability can be exploited by an unauthenticated attacker.
What could an attacker obtain through successful exploitation?
A successful attack can leak the access token for the Compute Engine default service account.
What remediation is required?
Redeploy previously deployed apps. The vulnerability was patched on 01 June 2026.