Description
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.


This vulnerability was patched on 15 April 2026, and no customer action is needed.
Published: 2026-07-17
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Firebase Studio before April 15, 2026 allowed an attacker to trigger the generation of signed Google Cloud Storage URLs that provide direct access to other users' deployed source code. The flaw consequently permits the theft of proprietary code and the exposure of any sensitive data such as API keys that may be stored in the workspace. CWE‑862 highlights that the root cause is an improper access control mechanism allowing unauthorized access to protected resources.

Affected Systems

Google Cloud Platform users who are currently running Firebase Studio versions released prior to April 15, 2026 are vulnerable. This includes any Firebase Studio workspace that may contain sensitive values; the issue is specific to the server‑side implementation and does not affect client‑side code directly.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity vulnerability. The EPSS score of less than 1 % suggests that while the probability of exploitation is low, it is not negligible and attackers could still successively invoke the vulnerable endpoint without authentication. The flaw is not listed in the CISA KEV catalog, implying that no widespread or known public exploits are currently linked to it. Attackers are likely to exploit this weakness by sending unauthenticated HTTP requests to the Firebase Studio API endpoint that triggers GCS URL signing, thereby retrieving source files from another tenant.

Generated by OpenCVE AI on August 1, 2026 at 08:23 UTC.

Remediation

Vendor Solution

This vulnerability was patched on April 15, 2026 on the server-side. As a precautionary measure, users who may have stored sensitive information such as API keys (e.g., GEMINI_API_KEY) within their Firebase Studio workspace may choose to rotate these keys. Instructions for rotating the GEMINI_API_KEY can be found at https://firebase.google.com/docs/studio/troubleshooting#rotate-gemini-key .


OpenCVE Recommended Actions

  • If you stored sensitive API keys such as GEMINI_API_KEY in Firebase Studio, rotate them as a precautionary measure.
  • Audit your workspaces for exposed secrets and remove or secure any that are unnecessary.
  • Enable and review Cloud Logging for GCS URL signing requests to detect suspicious activity.

Generated by OpenCVE AI on August 1, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud firebase Studio
Vendors & Products Google Cloud
Google Cloud firebase Studio

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed.
Title Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

Google Cloud Firebase Studio
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-07-17T15:28:50.317Z

Reserved: 2026-06-19T11:04:06.795Z

Link: CVE-2026-12715

cve-icon Vulnrichment

Updated: 2026-07-17T15:28:45.476Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:36:00Z

Weaknesses