CVE-2026-12879

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
CVSS

No CVSS.

Configurations

No configuration.

History

09 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 14:16

Updated : 2026-07-09 16:39


NVD link : CVE-2026-12879

Mitre link : CVE-2026-12879

CVE.ORG link : CVE-2026-12879


JSON object : View

Products Affected

No product.

CWE
CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')

CWE-610

Externally Controlled Reference to a Resource in Another Sphere