Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database.
Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients blocked it.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 10:16
Updated : 2026-05-12 15:09
NVD link : CVE-2026-7428
Mitre link : CVE-2026-7428
CVE.ORG link : CVE-2026-7428
JSON object : View
Products Affected
No product.
CWE
CWE-1392
Use of Default Credentials
