CVE-2026-12710

Summary

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.

The issue was patched on April 4, 2026; no customer action is required.

Affected Software

VendorProductVersion RangeStatus
Google CloudApplication Integration2025-04-28 < 2026-04-04affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

References