Description
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data.


This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
Published: 2026-07-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from of Google Cloud Apigee before 12 June 2026, allowing an authenticated user to read data that belongs to other tenants. It is classified as CWE‑441 (Confused Deputy) and CWE‑610 (Trust Boundary Violation). The flaw compromises confidentiality by enabling cross‑tenant data leakage. Based on the description, it is inferred that the vulnerability does not provide arbitrary code execution or denial‑of‑service capabilities.

Affected Systems

Google Cloud Apigee instances deployed with any version earlier than 12 June 2026 are affected. The flaw resides in the server‑side BigQuery DAO component of Apigee. No customer‑side update is required.

Risk and Exploitability

With a CVSS base score of 5.9, the vulnerability is assessed as moderate severity. An EPSS score of <1% indicates that the likelihood of exploitation is very low authenticated within the Apigee environment; no public exploits have been catalogued and the vendor has already applied a server patch, the overall risk to customers is minimal and no immediate remediation is required on the client side.

Generated by OpenCVE AI on July 29, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • No customer action is required; the vendor has already applied a server‑side least‑tenant Big reducing the risk associated with confused deputy cross‑tenant activity and investigate any anomalous access patterns.
  • If cross‑tenant data access is detected, engage with vendor support and review tenant data isolation configurations.
  • Implement tenant‑level identity and access management controls to restrict BigQuery permissions to the owning tenant only.

Generated by OpenCVE AI on July 29, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Apigee
Vendors & Products Google
Google cloud Apigee

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
Title Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
Weaknesses CWE-441
CWE-610
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/U:Clear'}


Subscriptions

Google Cloud Apigee
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-07-09T13:42:48.913Z

Reserved: 2026-06-22T09:35:44.962Z

Link: CVE-2026-12879

cve-icon Vulnrichment

Updated: 2026-07-09T13:42:43.697Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')

  • CWE-610

    Externally Controlled Reference to a Resource in Another Sphere