Executive brief
BigQuery Data Transfer Service is a Google Cloud service that enables automated, scheduled data movement between cloud storage systems. An authenticated attacker could exploit improper input validation in the JDBC driver by crafting malicious connection parameters, allowing remote code execution within the connector container and privilege escalation in the tenant project.
Technical details
The vulnerability is an improper input validation flaw in the JDBC driver component of BigQuery Data Transfer Service (versions prior to May 1, 2026). An authenticated attacker can craft malicious JDBC connection string parameters to achieve remote code execution (RCE) within the connector container and subsequently escalate privileges to the tenant project level. The attack requires authentication to the service, making it a post-authentication privilege escalation vector. The vulnerability was patched on May 1, 2026, and all affected versions should be updated to the patched release.
Affected products
- Google BigQuery Data Transfer Service prior to May 1, 2026
Timeline
- 2026-05-01: patched
- 2026-08-26: disclosed