2026-06-22 15:20CVE-2026-8934GoogleCloud
PUBLISHED5.2CWE-862

Cross-Project Information Leakage in Google App Engine UI

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request.

This vulnerability was patched on 7 April 2026, and no customer action is needed.

Problem type

Affected products

Google Cloud

Cloud Console UIs

< 2026-04-07 - AFFECTED

References

GitHub Security Advisories

GHSA-5xr4-qrm5-m2w8

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine...

https://github.com/advisories/GHSA-5xr4-qrm5-m2w8

A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request.

This vulnerability was patched on 7 April 2026, and no customer action is needed.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-8934
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-8934",
    "assignerOrgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
    "assignerShortName": "GoogleCloud",
    "dateUpdated": "2026-06-22T16:29:08.221Z",
    "dateReserved": "2026-05-19T10:54:39.724Z",
    "datePublished": "2026-06-22T15:20:05.139Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
        "shortName": "GoogleCloud",
        "dateUpdated": "2026-06-22T15:20:05.139Z"
      },
      "title": "Cross-Project Information Leakage in Google App Engine UI",
      "descriptions": [
        {
          "lang": "en",
          "value": "A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request.\n\nThis vulnerability was patched on 7 April 2026, and no customer action is needed.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request.<br><br>This vulnerability was patched on 7 April 2026, and no customer action is needed.<br>"
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Google Cloud",
          "product": "Cloud Console UIs",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "date",
              "lessThan": "2026-04-07"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-862 Missing Authorization",
              "cweId": "CWE-862",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-038"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-1",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Michael Dalton",
          "type": "reporter"
        },
        {
          "lang": "en",
          "value": "Arvin Shivram",
          "type": "reporter"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-06-22T16:29:08.221Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}