Security bulletins

This page describes all security bulletins related to BigQuery.

GCP-2026-047

Published: 2026-07-13

Description Severity Notes

A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise.

What should I do?

No customer action is required. Google has already applied mitigations to all impacted products and services.

What vulnerabilities are being addressed?

During repository creation, an authenticated attacker could potentially escalate their permissions and perform cross-tenant repository takeover.

Critical CVE-2026-14934