Improper Privilege Management Vulnerability in Looker Studio Affects JDBC-Based Connectors
CVE-2025-12405
7.7HIGH
What is CVE-2025-12405?
An improper privilege management flaw was identified in Looker Studio, where users with report view access could copy reports and execute arbitrary SQL queries. This misuse arises from the stored credentials in the reports that interact with the underlying data source. The vulnerability is particularly concerning as it allows unauthorized SQL command execution, potentially leading to unauthorized data access or manipulation. Thankfully, this issue was resolved with a patch released on July 21, 2025, requiring no further action from customers.
Affected Version(s)
Looker Studio 0 < 2025-07-21
