A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations.

Apigee-X was found to be vulnerable.

This vulnerability was patched in version 1-16-0-apigee-3. No user action is required for this.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 08 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 06 Dec 2025 05:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations. Apigee-X was found to be vulnerable. This vulnerability was patched in version 1-16-0-apigee-3. No user action is required for this.
Title Improper access control in Google Cloud Apigee-X allows cross-tenant Analytics modification and log data access.
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/U:Clear'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2025-12-08T17:43:20.219Z

Reserved: 2025-11-17T10:16:08.332Z

Link: CVE-2025-13292

cve-icon Vulnrichment

Updated: 2025-12-08T17:43:17.754Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-06T05:16:44.110

Modified: 2025-12-08T18:26:49.133

Link: CVE-2025-13292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses