Back

CRITICAL

Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.

Published May 26, 2026

Description

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.

For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.

Affected products

Remediation

Vendor solution

For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release  1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 .

For Apigee Hybrid: you must upgrade to one of the following security patch releases:

* for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GoogleCloud
Published May 26, 2026
Updated May 26, 2026
Reserved Feb 9, 2026
CISA Vulnrichment
Updated May 26, 2026
NVD
Status Awaiting Analysis
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GoogleCloud
Published May 26, 2026
Updated May 26, 2026
Exploited since n/a
EUVD-2026-31865