Back to search
CVE-2026-2244
Published: Feb 26, 2026
Modified: Feb 26, 2026
PUBLISHED
Description
A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script. All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.
| Vendor | Product | Versions |
|---|---|---|
Google Cloud | Vertex AI Workbench | affected 7/21/2025 - < 01/30/2026 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now