EUVD Vulnerability Catalog

EUVD-2026-68433

Severity: CRITICAL Base Score: 9.4 CVSS Version: 4.0

Vulnerability Description

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is needed.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

Attack Vector (AV): Network
Attack Complexity (AC): Low
Attack Requirements (AT): None
Privileges Required (PR): Low
User Interaction (UI): Passive
Vulnerability Confidentiality Impact (VC): High
Vulnerability Integrity Impact (VI): High
Vulnerability Availability Impact (VA): High
Subsequent Confidentiality Impact (SC): High
Subsequent Integrity Impact (SI): High
Subsequent Availability Impact (SA): High
U: Clear

Affected Vendors & Systems

Vendor Google Cloud

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

GoogleCloud

EPSS Probability

0

Known Aliases
CVE-2026-19410 GHSA-q4ww-hvh7-426w
Published On

2026-08-31

Last Updated

2026-08-31