CVE-2026-81867: Deserialization of Untrusted Data in Application Integration allows Remote Code Execution

Published Sep 28, 2026
·
Updated

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.

This vulnerability was patched on 28 June 2026, and no customer action is needed.

Affected Software

1 affected component
Google Google Cloud Application Integration JavaScript Task<2026-06-28

Event History

Sep 28, 2026
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who could exploit this vulnerability?

An authenticated user with standard permissions could exploit it. The issue affects the JavaScript Task in Google Cloud Application Integration and enables code execution on shared production servers.

2

What does an attacker need to do to exploit it?

The attacker needs authenticated access and must use a specially crafted script that bypasses parameter guards.

3

Are deployments still affected or is customer action required?

The vulnerability was patched on 28 June 2026. The provided advisory states that no customer action is needed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203