Vulnerability Description
A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-12710?
CVE-2026-12710 is a documented vulnerability. A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal d...
How severe is CVE-2026-12710?
CVSS scoring is not yet available for CVE-2026-12710. Check NVD for updates.
Is there a patch for CVE-2026-12710?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.