Impact
The vulnerability arises from of Google Cloud Apigee before 12 June 2026, allowing an authenticated user to read data that belongs to other tenants. It is classified as CWE‑441 (Confused Deputy) and CWE‑610 (Trust Boundary Violation). The flaw compromises confidentiality by enabling cross‑tenant data leakage. Based on the description, it is inferred that the vulnerability does not provide arbitrary code execution or denial‑of‑service capabilities.
Affected Systems
Google Cloud Apigee instances deployed with any version earlier than 12 June 2026 are affected. The flaw resides in the server‑side BigQuery DAO component of Apigee. No customer‑side update is required.
Risk and Exploitability
With a CVSS base score of 5.9, the vulnerability is assessed as moderate severity. An EPSS score of <1% indicates that the likelihood of exploitation is very low authenticated within the Apigee environment; no public exploits have been catalogued and the vendor has already applied a server patch, the overall risk to customers is minimal and no immediate remediation is required on the client side.
OpenCVE Enrichment