CVE-2026-12717 CRITICAL

CVE-2026-12717: Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection

Vendor Google Cloud
Product BigQuery Data Transfer Service
Weakness CWE-74
Published August 26, 2026
Last update August 26, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

What the vulnerability does

01Description

An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.

Key dates

02Disclosure timeline

August 26, 2026 CVE published
August 26, 2026 Record updated

Related vulnerabilities

04Related CVE