Skip to content
Google CloudCVE-2026-14934

Google Cloud BigQuery: missing authorization

Critical9.4CVE-2026-14934 · Published Jul 13, 2026

A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
BigQuery
Product
>= 2025-10, < 2026-05-102026-05-10
Colab Enterprise
Product
>= 2025-10, < 2026-05-102026-05-10
Dataform
Product
>= 2025-10, < 2026-05-102026-05-10
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-862

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Application Integration: missing authorization
Critical9.3Aug 22
Google SecOps (Chronicle SOAR): SQL injection
Critical9.4Aug 17
Google SecOps (Chronicle SOAR): privilege escalation
Critical9.4Aug 5
Google Cloud Looker: cross-site scripting
High8.7Jul 24
Google Cloud Firebase Studio: missing authorization
High8.5Jul 17
Google Cloud Apigee: improper input validation
Medium5.9Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.