Google CloudCVE-2026-12879
Google Cloud Apigee: improper input validation
Medium5.9CVE-2026-12879 · Published Jul 9, 2026
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data. This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apigee Product | < 2026-06-12 | 2026-06-12 |
Details and references
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22 | Google Cloud Application Integration: missing authorization | Critical9.3 | 2026-04-04 |
| Aug 17 | Google SecOps (Chronicle SOAR): SQL injection | Critical9.4 | 6.3.85 |
| Aug 5 | Google SecOps (Chronicle SOAR): privilege escalation | Critical9.4 | 6.3.85 |
| Jul 24 | Google Cloud Looker: cross-site scripting | High8.7 | 25.6.103+3 more |
| Jul 17 | Google Cloud Firebase Studio: missing authorization | High8.5 | 2026-04-15 |
| Jul 13 | Google Cloud BigQuery: missing authorization | Critical9.4 | 2026-05-10+2 more |