Skip to content
Google CloudCVE-2026-12715

Google Cloud Firebase Studio: missing authorization

High8.5CVE-2026-12715 · Published Jul 17, 2026

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
Firebase Studio
Product
< 2026-04-152026-04-15
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Application Integration: missing authorization
Critical9.3Aug 22
Google SecOps (Chronicle SOAR): SQL injection
Critical9.4Aug 17
Google SecOps (Chronicle SOAR): privilege escalation
Critical9.4Aug 5
Google Cloud Looker: cross-site scripting
High8.7Jul 24
Google Cloud BigQuery: missing authorization
Critical9.4Jul 13
Google Cloud Apigee: improper input validation
Medium5.9Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.