Vulnerability Description
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine request logs from other projects using a specially crafted request. This vulnerability was patched on 7 April 2026, and no customer action is needed.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-8934?
CVE-2026-8934 is a documented vulnerability. A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine re...
How severe is CVE-2026-8934?
CVSS scoring is not yet available for CVE-2026-8934. Check NVD for updates.
Is there a patch for CVE-2026-8934?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.