Improper Input Validation in CData JDBC Driver Integration on Google Cloud Platform
CVE-2026-12717

9.4CRITICAL

Key Information:

Vendor
CVE Published:
26 August 2026

What is CVE-2026-12717?

An Improper Input Validation vulnerability in the CData JDBC driver integration for the Google Cloud BigQuery Data Transfer Service enables authenticated attackers to execute arbitrary code remotely within the connector container. This flaw arises from insufficient validation of JDBC connection string parameters, which can lead to privilege escalation within the tenant project. The issue impacts versions released prior to May 1, 2026, and has been addressed in subsequent updates. Users are not required to take any action following the patch.

Affected Version(s)

BigQuery Data Transfer Service 0 < 2026-05-01

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomas LaĹľauninkas
.