Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 9, 2026
Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-12879
Description
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data.
This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.