CVE-2026-81867: Deserialization of Untrusted Data in Application Integration allows Remote Code Execution
A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.
This vulnerability was patched on 28 June 2026, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
Who could exploit this vulnerability?
An authenticated user with standard permissions could exploit it. The issue affects the JavaScript Task in Google Cloud Application Integration and enables code execution on shared production servers.
What does an attacker need to do to exploit it?
The attacker needs authenticated access and must use a specially crafted script that bypasses parameter guards.
Are deployments still affected or is customer action required?
The vulnerability was patched on 28 June 2026. The provided advisory states that no customer action is needed.