Junglewise Threat Intelligence

CVE-2026-12879: Google Cloud Apigee improper input validation in BigQuery DAO

CVE-2026-12879 · Severity: info · CVSS 5.9 · Published 2026-07-09

Vendors: Google.

Executive brief

A security vulnerability in Google Cloud Apigee's data access component could have allowed an authorized user to access data belonging to other customers. Apigee is a platform used by businesses to design, secure, and scale application programming interfaces (APIs). Google has already applied a fix to its servers, and no action is required from customers to protect their data.

Technical details

An improper input validation vulnerability exists in the BigQuery Data Access Object (DAO) component of Google Cloud Apigee. The flaw is categorized as a 'Confused Deputy' (CWE-441) and an 'Externally Controlled Reference to a Resource in Another Sphere' (CWE-610). An authenticated attacker with high privileges could exploit this to bypass tenant isolation and exfiltrate data belonging to other tenants. The vulnerability affected Apigee X and was patched server-side by Google on June 12, 2026; Apigee hybrid was not affected.

Affected products

  • Google Cloud Apigee prior to 2026-06-12

Timeline

  • 2026-06-12: patched: Vulnerability patched on Apigee Servers
  • 2026-07-08: advisory: Release notes published by Google Cloud
  • 2026-07-09: disclosed: CVE published to NVD

References

Related threats