OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-81867 (CVSS 9.4)

NVD · officialPublished Sep 28, 2026Risk 50/100

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards. This vulnerability was patched on 28 June 2026, and no customer action is needed.

CVSS
9.4
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source