A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network resources via crafted requests to the production cluster. This vulnerability was patched and no customer action is needed.
History

Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Appsheet
Appsheet appsheet Web (main Server)
Vendors & Products Appsheet
Appsheet appsheet Web (main Server)

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
Description A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authenticated remote attacker to read sensitive local files and access internal network resources via crafted requests to the production cluster. This vulnerability was patched and no customer action is needed.
Title Arbitrary File Read and SSRF in Google AppSheet
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published: 2026-02-19T15:21:38.382Z

Updated: 2026-02-19T19:55:23.508Z

Reserved: 2026-02-10T11:57:47.527Z

Link: CVE-2026-2274

cve-icon Vulnrichment

Updated: 2026-02-19T19:55:17.343Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-19T16:27:16.287

Modified: 2026-02-20T13:49:47.623

Link: CVE-2026-2274

cve-icon Redhat

No data.