CVE-2026-12717
Received Received - Intake

Remote Code Execution in Google Cloud BigQuery Data Transfer Service

Vulnerability report for CVE-2026-12717, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: GoogleCloud

Description

An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google cloud_bigquery_data_transfer_service to 2026-05-01 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Input Validation issue in the CData JDBC driver used by Google Cloud BigQuery Data Transfer Service. It allows an authenticated attacker to execute remote code within the connector container and escalate privileges in the tenant project by manipulating JDBC connection string parameters.

Detection Guidance

Detection requires checking the version of Google Cloud BigQuery Data Transfer Service. The vulnerability affects versions prior to 2026-05-01. Use the command 'gcloud beta services list --enabled --filter=name:bigquerydatatransfer.googleapis.com' to check the service version.

Impact Analysis

An attacker could exploit this to run malicious code remotely, potentially accessing or modifying sensitive data, disrupting services, or gaining higher-level access within your cloud environment. The impact depends on the permissions of the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating confidentiality requirements in GDPR and HIPAA. Organizations using the affected service may face compliance violations, legal penalties, or reputational damage if exploited.

Mitigation Strategies

No action is required as the vulnerability was patched on 1 May 2026. Ensure your service is updated to the latest version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12717. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart