CVE-2026-3136
EUVD-2026-930203.03.2026, 17:16
An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is needed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cloud_build | 𝑥 < 2026-1-26 |
𝑥
= Vulnerable software versions