Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

Google Cloud Vertex AI Workbench Exposes Access Tokens

CVE-2026-2244
Summary

Some users of Google Cloud Vertex AI Workbench, a tool for machine learning and data analysis, could have had their access tokens stolen by an attacker between July 21, 2025 and January 30, 2026. This could have allowed the attacker to access the affected user's Google Cloud account. Fortunately, Google has fixed the issue and all users are now protected.

Original title
A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup scr...
Original description
A vulnerability in Google Cloud Vertex AI Workbench from 7/21/2025 to 01/30/2026 allows an attacker to exfiltrate valid Google Cloud access tokens of other users via abuse of a built-in startup script.

All instances after January 30th, 2026 have been patched to protect from this vulnerability. No user action is required for this.
nvd CVSS4.0 8.4
Vulnerability type
CWE-200 Information Exposure
Published: 26 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026