CVE-2026-2031Disclosure

MEDIUMCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive internal information and execute arbitrary code using specially crafted HTTP requests to inadvertently exposed internal API endpoints.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-23); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-05-15: 1Mentions · 2026-05-24: 2Mentions · 2026-05-26: 1Mentions · 2026-06-23: 3Mentions · 2026-09-18: 1PoC Mentioned / Linked · 2026-05-24: 1Active Exploitation · 2026-06-23: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-24: 2Technical Details · 2026-06-23: 3Technical Details · 2026-09-18: 105-1505-2405-2606-2309-18
Signal classification3 categories
Disclosure
562.5%
General
225.0%
Active Exploitation
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-151
Disclosure1
2026-05-242
Disclosure2
2026-05-261
General1
2026-06-233
Active Exploitation1Disclosure1General1
2026-09-181
Disclosure1
Full discourse8 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    هذي المكافئات ولا بلاش نص مليون ريال ( $148,337 ) مكافئه اكتشاف ثغره في Google Cloud ـCVE: CVE-2026-2031 ـ مكافأة: $148,337 (مليون وأربعمائة ألف ريال سعودي تقريباً) التقييم CVSS 10/10 ـ CWE-862 (Missing Authorization) اكتشف باحثين ثغرتين منفصليتين وفي محادثه ديسكورد بالصدفه جمعو الثغرتين مع بعض وصارت RCE وحصلو على هالمكافئه الي وده يقرا التفاصيل التقنيه https://brutecat.com/articles/google-cloud-rce/

    Post summary

    The announcement details a Google Cloud RCE vulnerability (CVE‑2026‑2031) with a bounty of $148,337, providing CVSS and CWE information and a link to technical details, but no exploit code or active exploitation is reported.

    610015214130.6K
    50.0K followersView on X
  • Sam Stepanyan@securestep9
    Disclosure

    $148,337 #BugBounty paid by Google to a researcher (@brutecat) who found debug endpoints on Google Cloud allowing to configure privileged workflows leading to full #RCE in Google Cloud production (CVE-2026-2031) #CloudSecurity #BugBountyTips 👇 https://brutecat.com/articles/google-cloud-rce/

    Post summary

    The tweet announces a newly disclosed CVE (2026-2031) where debug endpoints on Google Cloud enable privileged workflow configuration, resulting in full RCE, and notes the reception of a bug bounty from Google.

    02053793
    7.4K followersView on X
  • Daily Bug Bounty Reports@Bug_Breakdown
    Disclosure

    A $148,337 payout for turning a simple API info leak into a full RCE in Google Cloud Production. Bug: Arbitrary Internal RPC Execution / RCE in Google Cloud (CVE-2026-2031) The Flaw: Google left internal debugging endpoints exposed on a Cloud CRM integration API. One specific endpoint allowed the researcher to dump the exact schema of any internal Google protobuf message—essentially acting as "req2proto as a Service". The Exploit: By using the leaked schemas and forcing base64 proto responses (?alt=proto), the researcher read internal workflow queues. They then escalated this by configuring a GenericStubbyTypedTask workflow, allowing them to execute arbitrary internal Stubby (gRPC) calls using Google's own production service identity (LOAS). Methodology Tip: In massive microservice architectures, gaining the ability to perform arbitrary internal RPC calls is often classified as a full RCE because it completely bypasses external access controls and exposes the entire production backend. Full breakdown of this insane privilege escalation in the replies 👇 #BugBounty #GoogleCloud #InfoSec #CyberSecurity #BugBountyReports #BugBountyTips #InfoSec

    Post summary

    This is a bug bounty disclosure reporting a critical RCE in Google Cloud Production (CVE-2026-2031) via exposed internal debugging endpoints allowing arbitrary gRPC calls. No PoC, exploit tool, patch, or active exploitation is confirmed in the text itself.

    20010227
    59 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Google Cloud Critical: CVE-2026-2031 Unauthenticated access + exposed internal APIs + potential code execution in Google Cloud Application Integration. This is the type of cloud issue attackers love - “internal” services accidentally exposed and suddenly becoming internet-facing risks. Running on Google Cloud? This one is worth checking ASAP. 👀Details: https://nvd.nist.gov/vuln/detail/CVE-2026-2031 #CyberSecurity #GoogleCloud #CloudSecurity #CVE20262031

    Post summary

    The tweet announces a critical Google Cloud vulnerability (CVE‑2026‑2031) with unauthenticated access and potential code execution, but does not provide PoC, exploitation details, or recovery guidance.

    00021101
    196 followersView on X
  • Israel@f1tym1
    General

    Arvin Shivram earned $148,337 from Google for discovering CVE-2026-2031, a critical RCE flaw in Application Integration service. https://ift.tt/ZcgjJFz

    Post summary

    Google awarded a bounty to Arvin Shivram for finding CVE-2026-2031, a critical RCE flaw in the Application Integration service; the post lacks details on exploitation, PoC, patch, or active usage.

    0001039
    1.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-5426 2 - CVE-2023-29218 3 - CVE-2026-2031 4 - CVE-2026-41096 5 - CVE-2024-53141 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists the top five trending CVEs without providing any detailed information, PoC, exploit code, or mitigation guidance.

    00010199
    1.7K followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    💰 Researcher Arvin Shivram earned $148,337 from Google after chaining flaws in Cloud Application Integration into full remote code execution, now tracked as CVE-2026-2031 with a CVSS score of 10.0. 🔹 Started by spotting a debug API leaking internal protobuf schemas (incl. Google's CRM and YouTube stacks) 🔹 Leveraged a leaked client ID to create draft workflows and abuse "GenericStubbyTypedTaskV2" to trigger arbitrary internal RPC calls 🔹 Bypassed two-person approval by adding two attacker-controlled accounts to a workflow's ACL 🔹 Raced a partially-deployed fix across backend instances to keep the exploit alive 🔹 Found a second RCE chain months later via IDOR in the public API's "test cases" feature Payout breakdown: $60K (first chain) + $75K (second chain) + $13,337 (privilege escalation) = $148,337 total.

    Post summary

    The post recounts how researcher Arvin Shivram chained multiple flaws in Google Cloud Application Integration to achieve remote code execution, successfully exploited CVE-2026-2031 in the wild, and profited from the attack.

    0000055
    17 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    A security researcher earned $148,337 for uncovering a critical RCE vulnerability in Google Cloud's Application Integration service, now patched as CVE-2026-2031. This flaw could have allowed unauthorized code execution within Google's production environment, highlighting the importance of robust access controls in cloud services. #Security #GoogleCloud #RCE #Vulnerability #CloudSecurity #CVE20262031 https://thedailytechfeed.com/researcher-earns-148k-for-google-cloud-rce-discovery/

    Post summary

    A researcher uncovered a critical RCE in Google Cloud’s Application Integration service, earning a reward; the vulnerability has been patched. The post focuses on the disclosure and remediation of the issue.

    0000054
    429 followersView on X

Explore more