Skip to main content
Vulnerability Database/CVE-2026-19410

CVE-2026-19410: Google Cloud Build Auth Bypass Vulnerability

CVE-2026-19410 is an authorization bypass flaw in Google Cloud Build that lets attackers execute unreviewed code via webhook suppression. This post covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-19410 Overview

CVE-2026-19410 is an Incorrect Authorization vulnerability in the GitHub Trigger Comment Control feature of Google Cloud Build on Google Cloud Platform. The flaw allows a remote attacker to bypass the comment-based approval control through webhook suppression and execute unreviewed code inside the build environment. Google patched the issue on 24 June 2026, and no customer action is required. The weakness is categorized under CWE-345: Insufficient Verification of Data Authenticity. The vulnerability is tracked in the Google Cloud Build Release Notes.

Critical Impact

A remote attacker with limited privileges can execute unreviewed code in a Cloud Build environment, gaining access to build secrets, service account credentials, and downstream cloud resources.

Affected Products

  • Google Cloud Build on Google Cloud Platform (versions prior to the 24 June 2026 fix)
  • GitHub Trigger Comment Control feature within Cloud Build
  • Build pipelines relying on comment-based approval for pull request builds

Discovery Timeline

  • 2026-06-24 - Google Cloud Build releases the server-side patch
  • 2026-08-31 - CVE-2026-19410 published to NVD
  • 2026-08-31 - Last updated in NVD database

Technical Details for CVE-2026-19410

Vulnerability Analysis

Cloud Build's GitHub Trigger Comment Control feature is designed to gate builds behind a reviewer comment, such as /gcbrun, on pull requests submitted by external contributors. The control exists to prevent untrusted code in a pull request from executing in a privileged build environment before a maintainer reviews the change.

The vulnerability allows an attacker to suppress or manipulate the webhook payload sequence so that Cloud Build treats an unreviewed pull request as authorized. Because the comment control is enforced against event metadata rather than an independently verified authorization state, the trigger can be induced to run code that was never approved by a repository maintainer.

Once a build starts, the attacker's code inherits the identity and permissions of the Cloud Build service account. This exposes source repositories, artifact registries, and any Google Cloud resources reachable from that identity.

Root Cause

The root cause is insufficient verification of the authenticity and authorization state of the triggering event ([CWE-345]). The GitHub Trigger Comment Control accepted event data without correlating it to a validated approval record, allowing webhook suppression to defeat the comment gate.

Attack Vector

A remote attacker submits a pull request against a repository configured with a Cloud Build GitHub trigger. The attacker then manipulates the delivery of GitHub webhook events to Cloud Build, suppressing or reordering events so that the approval check passes without a legitimate maintainer comment. Cloud Build proceeds to execute the pull request code inside the build environment. Refer to the Google Cloud Build Release Notes for the vendor description of the fix.

Detection Methods for CVE-2026-19410

Indicators of Compromise

  • Cloud Build executions tied to pull requests from external contributors that lack a corresponding approval comment in the GitHub pull request timeline.
  • Build logs referencing commits or branches from forks that were never merged or approved.
  • Unexpected use of Cloud Build service account credentials against Artifact Registry, Cloud Storage, or Secret Manager.

Detection Strategies

  • Reconcile Cloud Build trigger events with GitHub audit logs to confirm that every external pull request build has a matching maintainer approval comment.
  • Alert on Cloud Build runs whose sourceProvenance points to an unmerged fork branch.
  • Correlate GitHub webhook delivery logs with Cloud Build invocation timestamps to identify suppressed or replayed events.

Monitoring Recommendations

  • Enable Cloud Audit Logs for cloudbuild.googleapis.com and forward them to a central analytics platform for retention and correlation.
  • Monitor for anomalous egress, credential retrieval, or IAM token use originating from Cloud Build worker pools.
  • Track service account key and OAuth token usage tied to Cloud Build identities for out-of-pattern activity.

How to Mitigate CVE-2026-19410

Immediate Actions Required

  • Confirm the fix is in place by reviewing the Cloud Build Release Notes; Google applied the patch server-side on 24 June 2026.
  • Audit Cloud Build execution history from before the patch for pull request builds without matching approval comments.
  • Rotate any long-lived secrets, service account keys, or tokens that were accessible from affected build pipelines.

Patch Information

Google patched CVE-2026-19410 on 24 June 2026 in the Cloud Build managed service. The vendor states no customer action is needed for the fix itself. Customers should still verify their trigger configurations and investigate historical builds for prior abuse.

Workarounds

  • Restrict GitHub triggers to run only on branches and events from trusted collaborators, and disable automatic builds on pull requests from forks where feasible.
  • Apply least-privilege IAM to the Cloud Build service account, removing access to Secret Manager, Artifact Registry, and production resources not required by the pipeline.
  • Use dedicated worker pools with network egress controls for builds that process external pull request code.
  • Require manual approval steps in Cloud Deploy or a downstream gate before build artifacts reach production environments.
bash
# Example: tighten a Cloud Build GitHub trigger to require an approving comment
# and disable builds from forked pull requests
gcloud builds triggers update github TRIGGER_NAME \
  --require-approval \
  --comment-control=COMMENTS_ENABLED \
  --pull-request-pattern='^main$' \
  --no-include-forks

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.