Impact
An improper input validation flaw in the CData JDBC driver integration used by Google Cloud BigQuery Data Transfer Service allows an authenticated attacker to supply malicious JDBC connection string parameters that can be executed as code within the connector container. The vulnerability can lead to full remote code execution and privilege escalation to the tenant project, enabling an attacker to compromise all data and operations handled by the transfer service. It is a classic injection weakness as identified by CWE-74.
Affected Systems
Google Cloud BigQuery Data Transfer Service versions released before 2026-05-01 are impacted. The patch was issued on May 1 2026, and the vulnerability is fixed in all releases thereafter. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so the current public exploitation probability is unknown but it could be exploited by an authenticated user who can configure JDBC connection strings. Because the flaw requires valid credentials, the potential for compromise is high but would be limited to attackers who already have access to the target tenant. The patch removes the flaw, so the risk is mitigated for systems updated to the patched release.
OpenCVE Enrichment