CVE-2026-19486: A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions
Summary
A Server-Side Request Forgery vulnerability (SSRF, where an attacker tricks a server into making requests to internal systems it shouldn't access) exists in Google Cloud Gemini Enterprise Agent Platform App Builder versions before June 1, 2026. An attacker without authentication can exploit this to steal the Compute Engine default service account access token (a credential that grants permissions to cloud resources). The vulnerability was patched on June 1, 2026.
Solution / Mitigation
Users will need to redeploy their previously deployed apps to receive the patch.
Vulnerability Details
EPSS: 0.0%
September 11, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19486
First tracked: September 11, 2026 at 08:07 AM
Classified by LLM (prompt v3) · confidence: 92%