CVE-2026-66902: Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call

Published Aug 4, 2026
·
Updated

Google::Auth versions before 0.06 for Perl run a command named in an externalaccount credentials JSON via an ungated system call.

The Pluggable subclass reads credentialsource.executable.command from the credentials JSON and runs it as system($command), a single argument call that passes the whole string to /bin/sh -c. The executable's environmentvariables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. makecreds selects the Pluggable subclass whenever credentialsource.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "externalaccount" configuration read from the file named by GOOGLEAPPLICATIONCREDENTIALS. Configurations without credentialsource.executable do not select this subclass and do not reach the call.

Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.

Affected Software

1 affected component
Google::Auth (Perl)<0.06

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Google::Auth (Perl) to a version that resolves this vulnerability.

    Fixed in 0.06
  2. Configuration

    Ensure GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES is not set to 1 (leave unset or set to 0) so Google::Auth 0.06+ does not allow execution of credential_source.executable.command from external_account credentials JSON.

    Google::Auth (Perl) GOOGLE_EXTERNAL_ACCOUNT_ALLOW_EXECUTABLES = 0

Event History

Aug 4, 2026
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203