CVE-2026-19759: Incorrect Authorization in Application Integration allows Internal Stubby RPC Execution
An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an internal-only task type.
This vulnerability was patched on 17 June 2026, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
Who could exploit this issue?
Exploitation required an authenticated Google Cloud user. The issue affected task configurations in Google Cloud Application Integration versions prior to 17 June 2026.
What level of access could successful exploitation provide?
An attacker could execute arbitrary internal RPCs from within Google's production network using a privileged identity, through an internal-only task type.
Is customer remediation required?
No. The vulnerability was patched on 17 June 2026, and the provided advisory states that no customer action is needed.