Cloud Build: Incorrect Authorization Vulnerability in GitHub Trigger Comment Control Fixed
securitygcpsecurity-advisoryengineer
security
Google Cloud has fixed an incorrect authorization vulnerability, CVE-2026-19410, affecting Cloud Build's GitHub Trigger Comment Control. This security flaw could have allowed unauthorized actions within the build process. The fix has been applied automatically, and no customer action is required to secure their Cloud Build instances. This update enhances the integrity of CI/CD pipelines integrated with GitHub.
Security (1) ›
- Cloud Build
An Incorrect Authorization vulnerability CVE-2026-19410 , in GitHub Trigger Comment Control in Cloud Build, was fixed. No customer action is needed.
Read the original announcement →
https://docs.cloud.google.com/release-notes#August_24_2026
Related releases
- GCP Secure Web Proxy Adds Local Intermediate CA Signing Mode for TLS Inspection Google Cloud release notes ·
- Managed Airflow Agent Now Available in Google Cloud Console Google Cloud release notes ·
- Cloud Run Introduces Instances for Long-Lived Workloads in Preview Google Cloud release notes ·
- Google Cloud CCaaS Pre-Release Notes Detail Upcoming Agent Desktop Email Support & API Updates Google Cloud release notes ·
- Cloud Run functions Go runtime 1.24 reaches end of life in 7 days endoflife.date ·
- Cloud SQL for SQL Server Adds Specialized Endpoint URLs for MCP Server Google Cloud release notes ·