CVE-2026-12710 PUBLISHED

Missing Authorization in Application Integration QueryEngineTask

Assigner: GoogleCloud
Reserved: 19.06.2026 Published: 22.08.2026 Updated: 22.08.2026

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.

The issue was patched on April 4, 2026; no customer action is required.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/U:Clear
CVSS Score: 9.3

Product Status

Vendor Google Cloud
Product Application Integration
Versions Default: unaffected
  • affected from 2025-04-28 to 2026-04-04 (excl.)

Solutions

Access is now restricted and the issue is resolved.

Integrations using QueryEngineTask for external traffic will return a PERMISSION_DENIED error. We recommend that customers remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks in their Application Integration workflows.

Credits

  • Guillaume Berleur reporter

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs