This vulnerability was patched on 28 June 2026, and no customer action is needed.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed. | |
| Title | Deserialization of Untrusted Data in Application Integration allows Remote Code Execution | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-28T10:49:16.416Z
Reserved: 2026-08-27T17:44:48.468Z
Link: CVE-2026-81867
No data.
Status : Received
Published: 2026-09-28T11:16:48.070
Modified: 2026-09-28T11:16:48.070
Link: CVE-2026-81867
No data.
OpenCVE Enrichment
Updated: 2026-09-28T13:00:16Z