CVE-2026-12710: CWE-862 Missing Authorization in Google Cloud Application Integration
CVE-2026-12710 is a critical missing authorization vulnerability in the QueryEngineTask component of Google Cloud Application Integration. It affects versions from 2025-04-28 up to the patch date 2026-04-04. This flaw allows an external attacker to access sensitive internal data without proper authorization. The vulnerability was patched by Google on April 4, 2026, and no customer action is required as this is a cloud service with vendor-managed remediation.
AI Analysis
Technical Summary
This vulnerability (CWE-862) in Google Cloud Application Integration's QueryEngineTask component allows unauthorized external access to sensitive internal data due to missing authorization checks. It affects the cloud service versions from 2025-04-28 until the patch was applied on 2026-04-04. The CVSS 4.0 score is 9.3 (critical), indicating network attack vector with no privileges or user interaction required, and high impact on confidentiality and integrity. Since this is a cloud-hosted service, Google manages the patching process internally.
Potential Impact
An external attacker could exploit this vulnerability to access sensitive internal data within Google Cloud Application Integration without authorization. This could lead to data exposure and compromise of confidentiality and integrity of the affected service data.
Mitigation Recommendations
The vulnerability was patched by Google on April 4, 2026. As this is a cloud service, Google manages the remediation server-side, and no customer action is required. Customers should verify with the vendor advisory to confirm their environment is protected.
CVE-2026-12710: CWE-862 Missing Authorization in Google Cloud Application Integration
Description
CVE-2026-12710 is a critical missing authorization vulnerability in the QueryEngineTask component of Google Cloud Application Integration. It affects versions from 2025-04-28 up to the patch date 2026-04-04. This flaw allows an external attacker to access sensitive internal data without proper authorization. The vulnerability was patched by Google on April 4, 2026, and no customer action is required as this is a cloud service with vendor-managed remediation.
CVSS v4.0
Score 9.3critical
Affected software
pkg:github/googlecloud/application-integrationRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-862) in Google Cloud Application Integration's QueryEngineTask component allows unauthorized external access to sensitive internal data due to missing authorization checks. It affects the cloud service versions from 2025-04-28 until the patch was applied on 2026-04-04. The CVSS 4.0 score is 9.3 (critical), indicating network attack vector with no privileges or user interaction required, and high impact on confidentiality and integrity. Since this is a cloud-hosted service, Google manages the patching process internally.
Potential Impact
An external attacker could exploit this vulnerability to access sensitive internal data within Google Cloud Application Integration without authorization. This could lead to data exposure and compromise of confidentiality and integrity of the affected service data.
Mitigation Recommendations
The vulnerability was patched by Google on April 4, 2026. As this is a cloud service, Google manages the remediation server-side, and no customer action is required. Customers should verify with the vendor advisory to confirm their environment is protected.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GoogleCloud
- Date Reserved
- 2026-06-19T10:49:27.988Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a895fd8acd9273b49ca788e
Added to database: 08/22/2026, 08:37:44 UTC
Last enriched: 08/22/2026, 08:52:02 UTC
Last updated: 08/22/2026, 09:13:26 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.