Agents
CVE-2026-19486: unauthenticated SSRF in Gemini Enterprise Agent Platform App Builder leaked the Compute Engine default service account token
A GitHub advisory published 2026-09-11 describes an SSRF in Google Cloud's Gemini Enterprise Agent Platform App Builder for versions before 2026-06-01. An unauthenticated attacker could use it to pull the Compute Engine default service account access token. Google patched it on 1 June, but apps deployed before then must be redeployed to pick up the fix. Anyone with long-lived App Builder agents should redeploy and audit what the default service account can reach.
↳ Follow the thread