gcp Google Cloud release notes ·

Cloud Build: Incorrect Authorization Vulnerability in GitHub Trigger Comment Control Fixed

securitygcpsecurity-advisoryengineer
security

Google Cloud has fixed an incorrect authorization vulnerability, CVE-2026-19410, affecting Cloud Build's GitHub Trigger Comment Control. This security flaw could have allowed unauthorized actions within the build process. The fix has been applied automatically, and no customer action is required to secure their Cloud Build instances. This update enhances the integrity of CI/CD pipelines integrated with GitHub.

Security (1)
  • Cloud Build

    An Incorrect Authorization vulnerability CVE-2026-19410 , in GitHub Trigger Comment Control in Cloud Build, was fixed. No customer action is needed.

Read the original announcement →

https://docs.cloud.google.com/release-notes#August_24_2026

Related releases