Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-065

A security flaw was discovered in Google Cloud's Application Integration JavaScript Task, where an authenticated user with standard permissions could run harmful code on shared production servers. Google fixed this issue on June 28, 2026, and no action is required from customers.

QCS published 2/10/2026, 6:18:45 am ISTVendor disclosure 28/9/2026, 3:27:41 pm ISTVerified 2/10/2026, 6:18:45 am ISTRevision 1

In plain language

What this advisory means

A security flaw was discovered in Google Cloud's Application Integration JavaScript Task, where an authenticated user with standard permissions could run harmful code on shared production servers. Google fixed this issue on June 28, 2026, and no action is required from customers.

Technical explanation

How the issue affects the environment

The vulnerability involves deserialization of untrusted data in the JavaScript Task component of Google Cloud's Application Integration. This flaw allowed an authenticated user with standard permissions to execute arbitrary code via a specially crafted script. This code execution occurred on the shared production servers, posing a critical risk to the cloud environment's integrity and security. Google patched the vulnerability on June 28, 2026, preventing exploitation through this attack vector.

Operational impact

Why teams should care

If exploited, this vulnerability could allow attackers to run unauthorized code on shared production servers, potentially leading to data compromise, service disruption, and loss of trust in Google Cloud services. However, because Google has already patched this issue, the risk to customers is mitigated with no required customer action.

Immediate action

Google has patched the vulnerability as of June 28, 2026. Customers do not need to take any action as the fix is applied on the server side within Google Cloud's infrastructure.

Affected and fixed releases

Affected versionsApplication Integration JavaScript Task versions prior to June 28, 2026
Fixed versionsVersions patched on or after June 28, 2026

Temporary risk reduction

No customer action or workaround is required or provided, as the issue is fully mitigated by Google's patch.

Evidence and validation checklist

  • Security bulletin published by Google Cloud on 2026-09-28.
  • Vulnerability patched on June 28, 2026.
  • Description of authenticated users with standard permissions able to execute arbitrary code.
  • CVE assigned: CVE-2026-81867.

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source