CVE-2026-12710

Published Aug 22, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-12710 describes a Missing Authorization vulnerability found within the QueryEngineTask component of Google Cloud Application Integration. This flaw allowed an external attacker to gain unauthorized access to sensitive internal data. The vulnerability affected versions of Google Cloud Application Integration released between April 28, 2025, and April 4, 2026. The issue was addressed and patched on April 4, 2026. Google has indicated that no customer action is required regarding this vulnerability, as the necessary remediation has been implemented.

Description
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.
Source
f45cbf4e-4146-4068-b7e1-655ffc2c548c
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity
CRITICAL

Weaknesses

f45cbf4e-4146-4068-b7e1-655ffc2c548c
CWE-862

Social media

Hype score
Not currently trending