SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19410

CRITICAL · CVSS 9.4 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical incorrect authorization vulnerability in GitHub's Trigger Comment Control for Google Cloud Build allows remote attackers to execute unreviewed code in the build environment via webhook suppression. Organizations utilizing GitHub on Google Cloud Platform should prioritize this issue to mitigate potential unauthorized code execution risks. Although the vulnerability has been patched as of June 24, 2026, awareness and monitoring are essential to ensure no residual exposure remains.

CVE
CVE-2026-19410
Severity
CRITICAL
CVSS
9.4
EPSS
0.20%
GitHub

Original NVD Description

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.