SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12710

CRITICAL · CVSS 9.3 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical Missing Authorization vulnerability in Google Cloud Application Integration's QueryEngineTask allows external attackers to access sensitive internal data in affected versions released between April 28, 2025, and April 4, 2026. Organizations using these versions should prioritize updating to the patched version released on April 4, 2026, to mitigate the risk of unauthorized data exposure.

CVE
CVE-2026-12710
Severity
CRITICAL
CVSS
9.3
EPSS
0.32%

Original NVD Description

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.