CVE-2026-14934
CRITICALCross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
Title source: cnaDescription
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.
References (1)
Core 1
Core References
Scores
CVSS v4
9.4
EPSS
0.0023
EPSS Percentile
13.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (3)
Google Cloud/BigQuery
2025-10 - 2026-05-10
Google Cloud/Colab Enterprise
2025-10 - 2026-05-10
Google Cloud/Dataform
2025-10 - 2026-05-10
Published
Jul 13, 2026
Tracked Since
Jul 13, 2026