Google CloudCVE-2026-14934
Google Cloud BigQuery: missing authorization
Critical9.4CVE-2026-14934 · Published Jul 13, 2026
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| BigQuery Product | >= 2025-10, < 2026-05-10 | 2026-05-10 |
| Colab Enterprise Product | >= 2025-10, < 2026-05-10 | 2026-05-10 |
| Dataform Product | >= 2025-10, < 2026-05-10 | 2026-05-10 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Google Cloud advisories
All Google Cloud| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 22 | Google Cloud Application Integration: missing authorization | Critical9.3 | 2026-04-04 |
| Aug 17 | Google SecOps (Chronicle SOAR): SQL injection | Critical9.4 | 6.3.85 |
| Aug 5 | Google SecOps (Chronicle SOAR): privilege escalation | Critical9.4 | 6.3.85 |
| Jul 24 | Google Cloud Looker: cross-site scripting | High8.7 | 25.6.103+3 more |
| Jul 17 | Google Cloud Firebase Studio: missing authorization | High8.5 | 2026-04-15 |
| Jul 9 | Google Cloud Apigee: improper input validation | Medium5.9 | 2026-06-12 |