Improper Privilege Management Vulnerability in Looker Studio Affects JDBC-Based Connectors
CVE-2025-12405
What is CVE-2025-12405?
An improper privilege management flaw was identified in Looker Studio, where users with report view access could copy reports and execute arbitrary SQL queries. This misuse arises from the stored credentials in the reports that interact with the underlying data source. The vulnerability is particularly concerning as it allows unauthorized SQL command execution, potentially leading to unauthorized data access or manipulation. Thankfully, this issue was resolved with a patch released on July 21, 2025, requiring no further action from customers.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Looker Studio 0 < 2025-07-21
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
