9.2
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber
Description
A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.
For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
AI Analysis
Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy
Basic Information
ID
CVE-2026-2264
Source
GoogleCloud
Published
May 26, 2026 at 16:30
Affected Product
Vendor
Google Cloud
Product
Apigee-X
Affected Versions
Google Cloud Apigee-X 0
Google Cloud Apigee-X 0
Google Cloud Apigee-X 0
Google Cloud Apigee-X 0
Google Cloud Apigee-X 0
CWE Classification
AI Assessment
AI Score
9.2 / 10
AI Severity
Critical
Vendor
Google Cloud
Product
Apigee-X