For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy.
No advisories yet.
Solution
For Apigee: no action is required for customers using the Google Cloud version of Apigee. Vulnerability fixes have been applied to Apigee release 1-16-0-apigee-5 https://docs.cloud.google.com/apigee/docs/release-notes#January_20_2026 . For Apigee Hybrid: you must upgrade to one of the following security patch releases: * for 1.14, upgrade to 1.14.4 * for 1.15, upgrade to 1.15.2 * for 1.16, upgrade to 1.16.1
Workaround
No workaround given by the vendor.
Tue, 26 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google cloud Apigee-x |
|
| Vendors & Products |
Google
Google cloud Apigee-x |
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure configuration of the API proxy. | |
| Title | Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetIntegrationRequest Policy. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-05-26T19:20:49.023Z
Reserved: 2026-02-09T19:20:21.637Z
Link: CVE-2026-2264
No data.
Status : Received
Published: 2026-05-26T17:16:30.760
Modified: 2026-05-26T17:16:30.760
Link: CVE-2026-2264
No data.
OpenCVE Enrichment
Updated: 2026-05-26T19:00:15Z