{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-19410", "assignerOrgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c", "state": "PUBLISHED", "assignerShortName": "GoogleCloud", "dateReserved": "2026-08-10T09:07:34.906Z", "datePublished": "2026-08-31T08:14:52.377Z", "dateUpdated": "2026-08-31T11:18:20.587Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c", "shortName": "GoogleCloud", "dateUpdated": "2026-08-31T08:14:52.377Z" }, "title": "Google Cloud Build Comment Control Bypass via Webhook Suppression", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-367", "description": "CWE-367 Time-of-check time-of-use (TOCTOU) race condition", "type": "CWE" } ] }, { "descriptions": [ { "lang": "en", "cweId": "CWE-345", "description": "CWE-345 Insufficient Verification of Data Authenticity", "type": "CWE" } ] } ], "impacts": [ { "capecId": "CAPEC-1", "descriptions": [ { "lang": "en", "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs" } ] } ], "affected": [ { "vendor": "Google Cloud", "product": "Google Cloud Build", "versions": [ { "status": "affected", "version": "0", "lessThan": "2026-06-24", "versionType": "date" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.\n\n\nThis vulnerability was patched on 24 June 2026, and no customer action is needed.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.