SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12717

CRITICAL · CVSS 9.4 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An Improper Input Validation vulnerability in the CData JDBC driver integration within Google Cloud BigQuery Data Transfer Service allows authenticated attackers to execute remote code and escalate privileges by manipulating JDBC connection string parameters. Organizations utilizing this service should prioritize remediation to prevent potential exploitation, although the issue has been addressed in the latest update released on May 1, 2026.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12717
Severity
CRITICAL
CVSS
9.4
EPSS
0.45%

Original NVD Description

An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.