CyberRota Analysis
AI-GeneratedA Confused Deputy vulnerability in the EmailTask component of Google Cloud Application Integration allows authenticated attackers to read and exfiltrate sensitive internal files by manipulating attachment file paths. Organizations utilizing this component prior to the patch release on June 30, 2026, should prioritize remediation to protect against potential data breaches. No customer action is needed for those who have updated to the patched version.
Original NVD Description
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed.