EUVD Vulnerability Catalog

EUVD-2026-68433

Severity: CRITICAL Base Score: 9.4 CVSS Version: 4.0

Vulnerability Description

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): Low
▪ User Interaction (UI): Passive
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): High
▪ Subsequent Integrity Impact (SI): High
▪ Subsequent Availability Impact (SA): High
▪ U: Clear

Affected Vendors & Systems

Vendor Google Cloud

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

GoogleCloud

EPSS Probability

0

Known Aliases
CVE-2026-19410 GHSA-q4ww-hvh7-426w
Published On

2026-08-31

Last Updated

2026-08-31