Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-066

A security flaw was found in the Email Task component of Google Cloud's Application Integration service. This flaw could let someone with access read internal Google files they shouldn't see by tricking the system with a fake attachment path. Google fixed this problem on June 30, 2026, and no action is needed from customers.

QCS published 2/10/2026, 2:44:42 am ISTVendor disclosure 28/9/2026, 3:27:41 pm ISTVerified 2/10/2026, 2:44:42 am ISTRevision 1

In plain language

What this advisory means

A security flaw was found in the Email Task component of Google Cloud's Application Integration service. This flaw could let someone with access read internal Google files they shouldn't see by tricking the system with a fake attachment path. Google fixed this problem on June 30, 2026, and no action is needed from customers.

Technical explanation

How the issue affects the environment

A Confused Deputy vulnerability in the Email Task component of Application Integration before June 30, 2026, allowed an authenticated attacker to exploit crafted attachment paths to access and exfiltrate arbitrary internal Google files. This vulnerability involves improper authorization checks leading to unauthorized file read operations within Google internal systems. The issue was patched by Google on June 30, 2026.

Operational impact

Why teams should care

If exploited, an attacker with valid credentials could read sensitive internal Google files, resulting in potential leakage of confidential or proprietary information. This could harm Google's operations and customer trust, though customer environments were not affected and needed no action.

Immediate action

Google has patched the vulnerability in Application Integration as of June 30, 2026. Customers do not need to take any action, as the fix has been applied by Google.

Affected and fixed releases

Affected versionsApplication Integration versions prior to June 30, 2026
Fixed versionsApplication Integration versions on and after June 30, 2026

Temporary risk reduction

No workaround is specified or required. The fix has been applied internally by Google; customers are advised to verify that their service version reflects the patched state.

Evidence and validation checklist

  • Official Google Cloud Security Bulletin GCP-2026-066
  • CVE assignment CVE-2026-81375
  • Patch applied on June 30, 2026
  • No required customer action stated

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source