Junglewise Threat Intelligence

CVE-2026-12710: Google Cloud Application Integration missing authorization in QueryEngineTask

CVE-2026-12710 · Severity: info · CVSS 0 · Published 2026-08-22

Vendors: Google.

Executive brief

Google Cloud Application Integration is a service for building enterprise integration workflows. A missing authorization vulnerability in the QueryEngineTask component allowed external attackers to access sensitive internal data without proper permission checks. The vulnerability was patched on April 4, 2026, and no customer action is required.

Technical details

This is a missing authorization (CWE-862) vulnerability in the QueryEngineTask component of Google Cloud Application Integration affecting versions released between April 28, 2025 and April 4, 2026. The vulnerable component fails to properly validate that an external caller has authorization to execute query operations, allowing unauthenticated or unauthorized access to internal data. The attack vector is network-based with no authentication required. Google patched this issue on April 4, 2026, and the patch was rolled out transparently without requiring customer action.

Affected products

  • Google Cloud Application Integration 2025-04-28 to 2026-04-04

Timeline

  • 2026-04-04: patched: Vulnerability patched; no customer action required
  • 2026-08-21: disclosed: Security advisory published in release notes
  • 2026-08-22: advisory: Published to NVD

References

Related threats