An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.
History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud bigquery Data Transfer Service
Vendors & Products Google Cloud
Google Cloud bigquery Data Transfer Service

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Description An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project using crafted JDBC connection string parameters. This vulnerability was patched on 1 May 2026, and no customer action is needed.
Title Remote Code Execution in BigQuery Data Transfer Service via JDBC Connection String Injection
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published: 2026-08-26T12:59:56.543Z

Updated: 2026-08-26T19:03:22.491Z

Reserved: 2026-06-19T11:20:27.072Z

Link: CVE-2026-12717

cve-icon Vulnrichment

Updated: 2026-08-26T19:03:18.215Z

cve-icon NVD

Status : Received

Published: 2026-08-26T14:17:07.250

Modified: 2026-08-26T20:17:00.417

Link: CVE-2026-12717

cve-icon Redhat

No data.