Missing Authorization in Google Cloud Application Integration
CVE-2026-12710

9.3CRITICAL

Key Information:

Vendor
CVE Published:
22 August 2026

What is CVE-2026-12710?

A Missing Authorization vulnerability exists in the QueryEngineTask of Google Cloud Application Integration, affecting versions released between April 28, 2025, and April 4, 2026. This flaw could allow external attackers to exploit the system and gain unauthorized access to sensitive internal data. Although a patch was released on April 4, 2026, and no customer action is necessary, users are encouraged to ensure they are running the latest version to mitigate any potential risks.

Affected Version(s)

Application Integration 2025-04-28 < 2026-04-04

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Guillaume Berleur
.