A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.
The issue was patched on April 4, 2026; no customer action is required.
Access is now restricted and the issue is resolved.
Integrations using QueryEngineTask for external traffic will return a PERMISSION_DENIED error. We recommend that customers remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks in their Application Integration workflows.