CVE-2026-14934
Awaiting Analysis Awaiting Analysis - Queue

Missing Authorization in Google Cloud BigQuery Dataform Colab Enterprise

Vulnerability report for CVE-2026-14934, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: GoogleCloud

Description

A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
google cloud_bigquery From 2025-10-01 (inc) to 2026-05-11 (exc)
google dataform From 2025-10-01 (inc) to 2026-05-11 (exc)
google colab_enterprise From 2025-10-01 (inc) to 2026-05-11 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authorization issue in the repository creation functionality of Google Cloud BigQuery, Dataform, and Colab Enterprise. It affects versions between October 2025 and May 10th, 2026 on the Google Cloud Platform.

An authenticated attacker could exploit this flaw to escalate their privileges and perform a cross-tenant repository takeover. This means the attacker could gain unauthorized access to repositories belonging to other tenants or organizations, potentially accessing or modifying sensitive data.

The vulnerability was patched on May 10, 2026, and no customer action is required as the fix has been applied.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the Missing Authorization vulnerability (CVE-2026-14934) in Google Cloud BigQuery, Dataform, or Colab Enterprise. Detection typically involves checking for unauthorized repository creation or privilege escalation attempts, but no technical details or commands are available in the given resources.

To detect potential exploitation, you may monitor logs for unusual repository creation activities or unauthorized access patterns in Google Cloud Platform services. However, the context does not provide actionable detection steps.

Impact Analysis

If you were using the affected versions of Google Cloud BigQuery, Dataform, or Colab Enterprise between October 2025 and May 10, 2026, this vulnerability could have impacted you in the following ways:

  • Unauthorized access to your repositories by an attacker, leading to data breaches or leaks of sensitive information.
  • Modification or deletion of repository contents, which could disrupt your operations or lead to data corruption.
  • Privilege escalation, where an attacker with limited access could gain higher-level permissions, increasing the scope of potential damage.
  • Cross-tenant attacks, where an attacker could access repositories belonging to other organizations or tenants, potentially exposing your data to third parties.

However, since the vulnerability was patched on May 10, 2026, and no customer action is needed, the risk has been mitigated for all users.

Compliance Impact

This vulnerability could have significant implications for compliance with common standards and regulations, depending on the nature of the data stored or processed in the affected services:

  • GDPR (General Data Protection Regulation): If the repositories contained personal data of EU citizens, unauthorized access or data breaches could violate GDPR requirements. Organizations may face fines of up to 4% of global revenue or €20 million, whichever is higher, for failing to protect personal data.
  • HIPAA (Health Insurance Portability and Accountability Act): If the repositories stored protected health information (PHI), a breach could result in violations of HIPAA's Privacy and Security Rules. This could lead to penalties ranging from $100 to $50,000 per violation, with a maximum of $1.5 million per year for each violation.
  • Other regulations: Depending on the industry, other standards like PCI DSS (for payment data), SOX (for financial data), or industry-specific regulations could be impacted if sensitive data was exposed or modified.

Since the vulnerability has been patched, organizations should ensure they are using the updated versions of the affected services to maintain compliance. However, if a breach occurred before the patch, organizations may need to report the incident to relevant authorities and affected individuals, depending on the regulations.

Mitigation Strategies

The vulnerability was patched on May 10, 2026, and no customer action is required if your systems are up to date. The context explicitly states that no additional steps are needed after the patch.

  • Ensure your Google Cloud BigQuery, Dataform, and Colab Enterprise instances are updated to versions released after May 10, 2026, to apply the patch.
  • Verify that your Google Cloud Platform environment is running the latest security updates by checking the official Google Cloud documentation or support bulletins.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14934. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart