VYPR
Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 9, 2026

Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy

CVE-2026-12879

Description

An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data.

This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.