https://seclists.org/oss-sec/2026/q3/435: CVE-2026-66902: Google::Auth versions befo0.06 for Perl run a command named in an external_account cdentials JSON via an ungated system call
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Google pypi/Google-Auth<0.06
Frequently Asked Questions
1
What is the severity of CVE-2026-66902?
CVE-2026-66902 is considered a high severity vulnerability due to the potential for arbitrary command execution.
2
How do I fix CVE-2026-66902?
To fix CVE-2026-66902, update Google::Auth to version 0.06 or later.
3
What software is affected by CVE-2026-66902?
CVE-2026-66902 affects Google::Auth versions prior to 0.06.
4
What type of vulnerability is CVE-2026-66902?
CVE-2026-66902 is a command injection vulnerability triggered by ungated system calls.
5
When was CVE-2026-66902 published?
CVE-2026-66902 was published on August 4, 2026.