Google · Cloud Application Integration · CVE-2026-19759
**Name of the Vulnerable Software and Affected Versions**
Google Cloud Application Integration versions prior to 2026-06-17
**Description**
An incorrect authorization issue in the task configuration allows an authenticated Google Cloud user to execute arbitrary internal RPCs (Remote Procedure Calls, which are calls to a function or procedure in a different address space) from within Google's production network. This is achieved by using an internal-only task type under a privileged identity.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.