Impact
A Missing Authorization vulnerability in the repository creation functionality of Google Cloud BigQuery, Dataform and Colab Enterprise allows an attacker who is already authenticated to create repositories in another tenant’s space, effectively taking over that tenant’s repositories. This can lead to unauthorized data access and modification. The weakness is classified as CWE‑862.
Affected Systems
Vulnerable versions were deployed between October 2025 and 10 May 2026. The affected products are Google Cloud BigQuery, Google Cloud Dataform and Google Cloud Colab Enterprise on the Google Cloud Platform. These services handle project‑specific data repositories and are used by multiple tenants within the same Google Cloud environment.
Risk and Exploitability
With a CVSS score of 9.4 the risk is high and the vulnerability was already patched as of 10 May 2026. No known exploitation data and the EPSS score is less than 1%, indicating a very low exploitation probability. Because the bug requires an authenticated user and the patch has been released, the practical risk is mitigated. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment