Improper Privilege Management Vulnerability in Looker Studio Affects JDBC-Based Connectors
CVE-2025-12405

7.7HIGH

Key Information:

Vendor
CVE Published:
10 November 2025

What is CVE-2025-12405?

An improper privilege management flaw was identified in Looker Studio, where users with report view access could copy reports and execute arbitrary SQL queries. This misuse arises from the stored credentials in the reports that interact with the underlying data source. The vulnerability is particularly concerning as it allows unauthorized SQL command execution, potentially leading to unauthorized data access or manipulation. Thankfully, this issue was resolved with a patch released on July 21, 2025, requiring no further action from customers.

Affected Version(s)

Looker Studio 0 < 2025-07-21

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Liv Matan from Tenable.
.
CVE-2025-12405 : Improper Privilege Management Vulnerability in Looker Studio Affects JDBC-Based Connectors