CVE-2026-12710

9.3

Google Cloud · Application Integration

A missing authorization flaw in the QueryEngineTask of Google Cloud Application Integration allowed unauthorized access to sensitive internal data.

Executive summary

A missing authorization vulnerability in Google Cloud Application Integration, now resolved by the vendor, potentially allowed unauthorized access to sensitive internal data.

Vulnerability

The vulnerability, categorized as CWE-862, existed within the QueryEngineTask. This flaw allowed unauthenticated external attackers to bypass authorization checks and access internal data, though the issue has since been remediated by Google at the service level.

Business impact

The vulnerability posed a significant risk of data exposure for affected integrations. Given the CVSS score of 9.3, the potential for unauthorized access to sensitive information constitutes a severe security incident, though the risk has been mitigated by the provider.

Remediation

Immediate Action: No customer action is required as Google has already applied the patch; however, administrators should review their integration workflows to remove or replace any remaining QueryEngineTask tasks as recommended by the vendor.

Proactive Monitoring: Review integration logs for any unexpected "PERMISSION_DENIED" errors or anomalous data access patterns that occurred prior to the April 2026 remediation.

Compensating Controls: Ensure that all cloud integrations follow the principle of least privilege and that sensitive data stores are protected by robust Identity and Access Management policies.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

While the vendor has mitigated the vulnerability, users of the Google Cloud Application Integration service should verify that their workflows are updated and align with the latest security guidance provided by the vendor. Ensure that any legacy tasks are cleaned up to maintain a secure integration environment.

More Google Cloud CVEs