Description
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover.


This vulnerability was patched on 10 May 2026, and no customer action is needed.
Published: 2026-07-13
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Missing Authorization vulnerability in the repository creation functionality of Google Cloud BigQuery, Dataform and Colab Enterprise allows an attacker who is already authenticated to create repositories in another tenant’s space, effectively taking over that tenant’s repositories. This can lead to unauthorized data access and modification. The weakness is classified as CWE‑862.

Affected Systems

Vulnerable versions were deployed between October 2025 and 10 May 2026. The affected products are Google Cloud BigQuery, Google Cloud Dataform and Google Cloud Colab Enterprise on the Google Cloud Platform. These services handle project‑specific data repositories and are used by multiple tenants within the same Google Cloud environment.

Risk and Exploitability

With a CVSS score of 9.4 the risk is high and the vulnerability was already patched as of 10 May 2026. No known exploitation data and the EPSS score is less than 1%, indicating a very low exploitation probability. Because the bug requires an authenticated user and the patch has been released, the practical risk is mitigated. It is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • No immediate action required; the issue was patched on 10 May 2026.
  • Continue to maintain proper tenant isolation in BigQuery, Dataform, and Colab Enterprise by ensuring project identifiers are correctly configured.
  • Regularly check the Google Cloud Support Bulletins and security advisories for any updates or related advisories.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Platform
Google Cloud
Google Cloud bigquery
Google Cloud colab Enterprise
Vendors & Products Google
Google cloud Platform
Google Cloud
Google Cloud bigquery
Google Cloud colab Enterprise

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.
Title Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

Google Cloud Platform
Google Cloud Bigquery Colab Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-07-13T13:12:16.784Z

Reserved: 2026-07-07T11:05:22.340Z

Link: CVE-2026-14934

cve-icon Vulnrichment

Updated: 2026-07-13T13:12:12.644Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses