天下漏洞,尽知其名
HIGH

CVE-2026-81867 Google Cloud Application Integration JavaScript Task 反序列化漏洞

影响已认证低权限用户可在共享生产服务器上执行任意代码

AI 研判

Google Cloud Application Integration 的 JavaScript Task 组件存在不可信数据反序列化漏洞。攻击者通过特制脚本绕过参数防护,在共享生产服务器上执行任意代码。该漏洞已于 2026 年 6 月 28 日修复。

影响范围

Google Cloud Application Integration

Google Cloud Platform 上 Google Cloud Application Integration 2026-06-28 之前的版本。

漏洞详情

漏洞类型为不可信数据反序列化。JavaScript Task 在处理用户提交的脚本时未充分校验,导致攻击者可绕过参数守卫注入恶意序列化数据,进而触发反序列化并在共享生产服务器上执行任意代码。

利用条件与风险

利用需具备标准权限的已认证账号,属于低权限用户越权提权,且影响共享生产环境,实战风险较高。

修复建议

官方已于 2026 年 6 月 28 日完成修复,客户无需采取额外操作;暂无公开的临时缓解措施。

原始情报

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing param guards.

This vulnerability was patched on 28 June 2026, and no customer action is needed.