Junglewise Threat Intelligence

CVE-2026-12717: Google BigQuery Data Transfer Service JDBC driver input validation bypass

CVE-2026-12717 · Severity: high · Published 2026-08-26

Executive brief

BigQuery Data Transfer Service is a Google Cloud service that enables automated, scheduled data movement between cloud storage systems. An authenticated attacker could exploit improper input validation in the JDBC driver by crafting malicious connection parameters, allowing remote code execution within the connector container and privilege escalation in the tenant project.

Technical details

The vulnerability is an improper input validation flaw in the JDBC driver component of BigQuery Data Transfer Service (versions prior to May 1, 2026). An authenticated attacker can craft malicious JDBC connection string parameters to achieve remote code execution (RCE) within the connector container and subsequently escalate privileges to the tenant project level. The attack requires authentication to the service, making it a post-authentication privilege escalation vector. The vulnerability was patched on May 1, 2026, and all affected versions should be updated to the patched release.

Affected products

  • Google BigQuery Data Transfer Service prior to May 1, 2026

Timeline

  • 2026-05-01: patched
  • 2026-08-26: disclosed

References

Related threats