Executive brief
Google Cloud AlloyDB for PostgreSQL is a fully managed, PostgreSQL-compatible database service. A security issue was identified where database clusters created via Terraform or the REST API prior to November 2025 could have been configured with an insecure default password. If exploited, a remote attacker with network access to the database could gain full administrative control, potentially leading to the theft, modification, or deletion of sensitive customer data.
Technical details
A vulnerability in the provisioning process of Google Cloud AlloyDB for PostgreSQL allowed for the creation of database clusters with insecure default credentials (CWE-1392). The issue specifically affected clusters created using Terraform or the direct REST API; other interfaces, such as the Google Cloud Console, reportedly blocked this behavior. An attacker with network reachability to the database instance could use these default credentials to gain full administrative (superuser) access to the PostgreSQL environment. Google has since updated the service so that if a password is not specified during creation, the 'postgres' role is created in a locked state with a null password.
Affected products
- Google Cloud AlloyDB for PostgreSQL Prior to 2025-11-03
Timeline
- 2025-11-03: patched: Date by which the insecure default behavior was remediated
- 2026-04-28: advisory: Release notes updated regarding locked postgres role behavior
- 2026-05-12: disclosed: CVE-2026-7428 published