Executive brief
A security flaw was identified in Google Cloud's BigQuery, Dataform, and Colab Enterprise services that could have allowed an authorized user to take control of data repositories belonging to other customers. These services are used for large-scale data analysis, workflow management, and collaborative data science. An exploit could have resulted in unauthorized access to sensitive corporate data or the disruption of critical data operations across different organizations.
Technical details
A missing authorization vulnerability (CWE-862) existed in the repository creation functionality of Google Cloud BigQuery, Dataform, and Colab Enterprise. The flaw allowed an authenticated attacker with low privileges to bypass intended access controls during the creation process, leading to privilege escalation and the ability to take over repositories belonging to other tenants (cross-tenant impact). The vulnerability was reachable over the network without user interaction. Google has patched the backend services, and the vulnerability is no longer exploitable; no customer action is required.
Affected products
- Google Cloud BigQuery October 2025 to May 10, 2026
- Google Cloud Dataform October 2025 to May 10, 2026
- Google Cloud Colab Enterprise October 2025 to May 10, 2026
Timeline
- 2026-05-10: patched: Vulnerability was mitigated by Google.
- 2026-07-13: disclosed: Public advisory published.