Security bulletins
This page describes all security bulletins related to
BigQuery.
GCP-2026-047
Published: 2026-07-13
| Description |
Severity |
Notes |
A Missing Authorization vulnerability was discovered in repositories
in BigQuery, Dataform, and Colab Enterprise.
What should I do?
No customer action is required. Google has already applied mitigations
to all impacted products and services.
What vulnerabilities are being addressed?
During repository creation, an authenticated attacker could
potentially escalate their permissions and perform cross-tenant
repository takeover. |
Critical |
CVE-2026-14934
|
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-29 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-29 UTC."],[],[]]