AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66902

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects Google::Auth versions prior to 0.06 for Perl, where an external command specified in the credentials JSON can be executed without proper validation through an ungated system call. This can lead to arbitrary command execution with the privileges of the application process, posing a significant security risk for applications that utilize external account credentials from untrusted sources. Organizations using affected versions should prioritize remediation, especially those handling sensitive data or operating in environments where credential integrity is critical.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66902
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "external_account" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call. Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.