← Back to search

CVE-2026-66902

9.8 CRITICALpublic exploit available

Published 2026-08-04 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows an attacker to execute arbitrary commands on the system where the vulnerable Google::Auth module is running, due to the lack of proper input validation and control over the command execution.
Exploitability
Exploitation is relatively straightforward as the command is executed without any gate or validation, requiring only control over the external_account credentials JSON.
Blast radius
If exploited, the impact could be severe, as it allows full system command execution with the privileges of the application process, potentially leading to complete system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Google::Auth version 0.06 or later.
rcecommand-executionauth-bypass

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the whole string to /bin/sh -c. The executable's environment_variables map from the same JSON is copied into %ENV first. No opt-in gate guards the call. make_creds selects the Pluggable subclass whenever credential_source.executable is present, so the path is reached from the standard Application Default Credentials flow, including a "type": "external_account" configuration read from the file named by GOOGLE_APPLICATION_CREDENTIALS. Configurations without credential_source.executable do not select this subclass and do not reach the call. Any caller that builds credentials from a configuration it does not fully control runs the embedded command with the privileges of the application process.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78, CWE-829

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.