PT-2026-89808 · Google Cloud · Gemini Enterprise Agent Platform App Builder

·

CVE-2026-19486

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Affected builds: 2025-10-11 through versions prior to 2026-06-01.
What it is: The backend could be induced to make a request on an attacker’s behalf and leak the Compute Engine default service account access token. That token is a short-lived OAuth credential for [PROJECT NUMBER-compute@developer.gserviceaccount.com ](mailto: PROJECT NUMBER-compute@developer.gserviceaccount.com ).
What the exposure is: On many projects that identity still has broad project access (often Editor, depending on scopes). A stolen token can mean API access to the project, not just a bug in a local app.
How to remediate: Google patched the platform on 1 June 2026. The platform fix does not automatically repair apps you already generated or deployed.
Redeploy previously deployed App Builder apps from the updated builder so the new backend ships. If you generated Agent Studio web apps before 1 July 2026 that use the auto-generated /api-proxy, regenerate and redeploy those too. The fixed backend allowlists destinations to Google Cloud domains. After redeploy, rotate anything that token could have touched. Stop running workloads as the default Compute Engine SA. Use a least-privilege custom service account. Restrict metadata/egress and confirm no pre-patch App Builder apps are still serving.
CVE Record: CVE-2026-19486

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19486

Affected Products

Gemini Enterprise Agent Platform App Builder