Description
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.




The issue was patched on April 4, 2026; no customer action is required.
Published: 2026-08-22
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw discovered in the QueryEngineTask of Google Cloud Application Integration enables an external attacker to retrieve sensitive internal data. The flaw has a CVSS score of 9.3, indicating high severity, and it permits unauthorized access to information that should be protected by existing controls. Because the vulnerability stems from a lack of proper access checks, an attacker could read data without needing valid credentials, potentially exposing confidential data.

Affected Systems

Google Cloud Application Integration, versions between 2025‑04‑28 and 2026‑04‑04. Workflows that contain any QueryEngineTask (ASIS_TEMPLATE) tasks are affected; these tasks can be invoked from external traffic and are the direct entry point to the vulnerability.

Risk and Exploitability

The CVSS score of 9.3 reflects the significant impact of the flaw, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. An attacker can exploit the vulnerability by invoking a QueryEngineTask over an external connection; no additional prerequisites are indicated, so the attack can be carried out by any external party with network reach to the integration. Because the issue is a missing authorization check, the attack vector is likely remote over the network and does not require credential compromise.

Generated by OpenCVE AI on August 22, 2026 at 10:33 UTC.

Remediation

Vendor Solution

Access is now restricted and the issue is resolved. Integrations using QueryEngineTask for external traffic will return a PERMISSION_DENIED error. We recommend that customers remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks in their Application Integration workflows.


OpenCVE Recommended Actions

  • Remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks from your integration workflows; those tasks will now return PERMISSION_DENIED errors.
  • Ensure any remaining QueryEngineTask usages within internal workflows are covered by proper authorization checks; if not, replace them with equivalent tasks that enforce access control.
  • Monitor integration logs for attempted QueryEngineTask invocations from external traffic and verify that only authorized services trigger tasks.

Generated by OpenCVE AI on August 22, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.
Title Missing Authorization in Application Integration QueryEngineTask
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Clear'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-08-22T08:13:00.095Z

Reserved: 2026-06-19T10:49:27.988Z

Link: CVE-2026-12710

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T09:16:53.340

Modified: 2026-08-22T09:16:53.340

Link: CVE-2026-12710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T10:45:03Z

Weaknesses