CVE-2026-12710: Google Cloud Application Integration

Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

Affected products

  • Google Cloud Application Integration: from 2025-04-28, before 2026-04-04 (fixed in 2026-04-04)

Published 2026-08-22. Last modified 2026-08-31.