Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Researcher Secures 8,337 for Google Cloud Vulnerability

Researcher Secures $148,337 for Google Cloud Vulnerability

Posted on June 23, 2026 By CWS

A cybersecurity researcher recently received $148,337 from Google for identifying significant vulnerabilities in the Google Cloud Application Integration service. These vulnerabilities escalated to remote code execution (RCE) within Google’s production environment.

Critical Vulnerability Details

Identified as CVE-2026-2031, the vulnerability is a serious access control issue in the Google Cloud Application Integration, achieving a maximum CVSS score of 10.0. Arvin Shivram, the researcher who discovered the flaw, detailed his findings in a blog post titled “StubZero: $148,337 RCE in Google Cloud Production” on BruteCat.

Shivram’s exploration began with an automated tool that detected anomalies in the API cloudcrmipfrontend-pa.googleapis.com, which returned suspicious debugging responses. This led to further investigation of an endpoint that disclosed internal message schemas, vital for understanding Google’s API structure.

Exploitation Process and Discovery

The research revealed an API surface that exposed internal workflow data through a specific endpoint. By leveraging this information and a leaked client ID, Shivram created draft workflows, exploring various internal tasks documented within Google’s system. The pivotal discovery involved the GenericStubbyTypedTaskV2 task, which allowed for arbitrary RPC calls using privileged service identities.

Through these actions, Shivram demonstrated how Stubby-level access could lead to RCE in Google’s production environment, a scenario that Google classifies under their Cloud Vulnerability Reward Program as granting significant internal access.

Google’s Response and Mitigation

Initially, Google mitigated the vulnerability by restricting endpoint access and enhancing security protocols. However, Shivram, collaborating with another researcher, identified that these mitigations were not fully implemented across all backend instances. By targeting vulnerable instances, they maintained the exploit path temporarily.

Additionally, a second vulnerability chain involving insecure direct object references (IDOR) was discovered, allowing access to sensitive workflow definitions across different tenants.

Significant Reward and Conclusion

For his findings, Google awarded Shivram a total of $148,337, reflecting the critical impact of his discoveries. This included $60,000 for the initial chain, $75,000 for the subsequent IDOR-related findings, and $13,337 for a single-service privilege escalation issue.

The research underscores the importance of continuous monitoring and security assessment within cloud environments. It also highlights the role of responsible disclosure and reward programs in enhancing cybersecurity defenses.

For more updates, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:ACL bypass, application integration, bug bounty, cloud security, CVE-2026-2031, Cybersecurity, Google Cloud, IDOR, RCE, researcher reward, RPC security, Stubby RPC, vulnerability disclosure, workflow exploitation

Post navigation

Previous Post: London Hydro Investigates Customer Data Breach
Next Post: Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Related Posts

DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment DOGE Accused of Creating Live Copy of the Country’s Social Security Information in Unsecured Cloud Environment Cyber Security News
Midnight Ransomware Decrypter Flaws Opens the Door to File Recovery Midnight Ransomware Decrypter Flaws Opens the Door to File Recovery Cyber Security News
Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware Mustang Panda Using New DLL Side-Loading Technique to Deliver Malware Cyber Security News
Enhance SOC Visibility to Reduce MTTR Effectively Enhance SOC Visibility to Reduce MTTR Effectively Cyber Security News
“CitrixBleed 2” Vulnerability PoC Released “CitrixBleed 2” Vulnerability PoC Released Cyber Security News
SAP Urges Immediate Patch for Critical Security Flaws SAP Urges Immediate Patch for Critical Security Flaws Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark