In plain language
What this advisory means
A security flaw was found in the Email Task component of Google Cloud's Application Integration service. This flaw could let someone with access read internal Google files they shouldn't see by tricking the system with a fake attachment path. Google fixed this problem on June 30, 2026, and no action is needed from customers.
Technical explanation
How the issue affects the environment
A Confused Deputy vulnerability in the Email Task component of Application Integration before June 30, 2026, allowed an authenticated attacker to exploit crafted attachment paths to access and exfiltrate arbitrary internal Google files. This vulnerability involves improper authorization checks leading to unauthorized file read operations within Google internal systems. The issue was patched by Google on June 30, 2026.
Operational impact
Why teams should care
If exploited, an attacker with valid credentials could read sensitive internal Google files, resulting in potential leakage of confidential or proprietary information. This could harm Google's operations and customer trust, though customer environments were not affected and needed no action.
Immediate action
Google has patched the vulnerability in Application Integration as of June 30, 2026. Customers do not need to take any action, as the fix has been applied by Google.
Affected and fixed releases
Temporary risk reduction
No workaround is specified or required. The fix has been applied internally by Google; customers are advised to verify that their service version reflects the patched state.
Evidence and validation checklist
- Official Google Cloud Security Bulletin GCP-2026-066
- CVE assignment CVE-2026-81375
- Patch applied on June 30, 2026
- No required customer action stated
Authoritative reference
Google Cloud Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
