VYPR

Apigee-X

by Google

CVEs (4)

  • CVE-2026-2264CriMay 26, 2026
    risk 0.60cvss epss 0.00

    A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For successful exploitation, an administrator must initially establish an insecure…

  • CVE-2025-13426HigDec 5, 2025
    risk 0.57cvss epss 0.00

    A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution. It is possible for a user to write a JavaCallout that injected a malicious object into the…

  • CVE-2025-13292HigDec 6, 2025
    risk 0.49cvss epss 0.00

    A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations. Apigee-X was found to be vulnerable. This vulnerability was patched in…

  • CVE-2026-12879MedJul 9, 2026
    risk 0.00cvss epss 0.00

    An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and…