Improper Input Validation in CData JDBC Driver Integration on Google Cloud Platform
CVE-2026-12717
9.4CRITICAL
What is CVE-2026-12717?
An Improper Input Validation vulnerability in the CData JDBC driver integration for the Google Cloud BigQuery Data Transfer Service enables authenticated attackers to execute arbitrary code remotely within the connector container. This flaw arises from insufficient validation of JDBC connection string parameters, which can lead to privilege escalation within the tenant project. The issue impacts versions released prior to May 1, 2026, and has been addressed in subsequent updates. Users are not required to take any action following the patch.
Affected Version(s)
BigQuery Data Transfer Service 0 < 2026-05-01
