CVE-2026-3136: Google Cloud Build Comment Control Bypass
Published Mar 3, 2026
·Updated
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment.
This vulnerability was patched on 26 January 2026, and no customer action is needed.
Affected Software
2 affected components
Google Cloud Build<2026-01-26
Google Cloud Build<2026-1-26
Event History
Mar 3, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 6, 58156
Event
via FIRST·05:12 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-3136?
CVE-2026-3136 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2026-3136?
To mitigate CVE-2026-3136, you should upgrade to Google Cloud Build version 2026-01-26 or later.
3
Who is affected by CVE-2026-3136?
Any users of Google Cloud Build prior to version 2026-01-26 are affected by CVE-2026-3136.
4
What type of attack does CVE-2026-3136 enable?
CVE-2026-3136 allows remote attackers to execute arbitrary code within the build environment.
5
When was CVE-2026-3136 patched?
CVE-2026-3136 was patched on January 26, 2026.