A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script.
All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.
All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this. | |
| Title | Sensitive Data Exposure in Google Cloud Vertex AI Workbench | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-02-26T14:59:56.045Z
Reserved: 2026-02-09T10:55:54.465Z
Link: CVE-2026-2244
No data.
Status : Received
Published: 2026-02-26T15:17:45.250
Modified: 2026-02-26T15:17:45.250
Link: CVE-2026-2244
No data.
OpenCVE Enrichment
No data.
Weaknesses