logo

CVE-2026-66902: Google::Auth Perl Library RCE via Credential JSON Injection

ID: 256de1f0-20e6-5ce7-8c31-d225dec77e9d

STIX ID: report--256de1f0-20e6-5ce7-8c31-d225dec77e9d

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-08-05

Date Updated: 2026-08-06

...
...

A critical command-injection vulnerability (CVE-2026-66902, CVSS 9.8) in Google::Auth (Perl) < 0.06 allows unauthenticated remote code execution by passing credential_source.executable.command into Perl's single-argument system(); the report details affected versions, attack vectors (malicious credentials, SSRF/path traversal, CI/CD injection, supply chain), impact, detection indicators, and recommends upgrading to 0.06 and hardening credential files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.