CVE-2026-2031

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.
CVSS

No CVSS.

Configurations

No configuration.

History

15 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 16:16

Updated : 2026-05-18 19:32


NVD link : CVE-2026-2031

Mitre link : CVE-2026-2031

CVE.ORG link : CVE-2026-2031


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization