OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-81375

HIGH · CVSS 8.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A Confused Deputy vulnerability in the EmailTask component of Google Cloud Application Integration allows authenticated attackers to read and exfiltrate sensitive internal files by manipulating attachment file paths. Organizations utilizing this component prior to the patch release on June 30, 2026, should prioritize remediation to protect against potential data breaches. No customer action is needed for those who have updated to the patched version.

CVE
CVE-2026-81375
Severity
HIGH
CVSS
8.3
EPSS
0.32%

Original NVD Description

A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June 2026, and no customer action is needed.