A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens.

For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.

Project Subscriptions

Vendors Products
Cloud Apigee-x Subscribe
Advisories

No advisories yet.

Fixes

Solution

For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release  1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 . For Apigee Hybrid: you must upgrade to one of the following security patch releases: * for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1


Workaround

No workaround given by the vendor.

History

Tue, 26 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Apigee-x
Vendors & Products Google
Google cloud Apigee-x

Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
Title Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy.
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-05-26T19:20:49.023Z

Reserved: 2026-02-09T19:20:21.637Z

Link: CVE-2026-2264

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-26T17:16:30.760

Modified: 2026-05-26T17:16:30.760

Link: CVE-2026-2264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T19:00:15Z

Weaknesses