« Back to list

Google

Google Cloud Build: vulnerabilities and CVEs

Google Cloud Build has 2 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19410Critical (9.4)0.14%—Aug 31, 2026
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment…
CVE-2026-3136High (8.6)0.41%—Mar 3, 2026
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter2
  2. T1203 Exploitation for Client Execution2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Google