Google CloudCVE-2026-12715
Google Cloud Firebase Studio: missing authorization
High8.5CVE-2026-12715 · Published Jul 17, 2026
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Firebase Studio Product | < 2026-04-15 | 2026-04-15 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22 | Google Cloud Application Integration: missing authorization | Critical9.3 | 2026-04-04 |
| Aug 17 | Google SecOps (Chronicle SOAR): SQL injection | Critical9.4 | 6.3.85 |
| Aug 5 | Google SecOps (Chronicle SOAR): privilege escalation | Critical9.4 | 6.3.85 |
| Jul 24 | Google Cloud Looker: cross-site scripting | High8.7 | 25.6.103+3 more |
| Jul 13 | Google Cloud BigQuery: missing authorization | Critical9.4 | 2026-05-10+2 more |
| Jul 9 | Google Cloud Apigee: improper input validation | Medium5.9 | 2026-06-12 |