CVE-2026-12879: Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an authenticated attacker to exfiltrate cross-tenant data.
This vulnerability was patched on 12 June 2026 on the Apigee Servers, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12879?
CVE-2026-12879 has a medium severity rating of 5.9 according to the CVSS score.
How do I fix CVE-2026-12879?
CVE-2026-12879 has been patched in Apigee versions released on June 12, 2026, so upgrading to that version or later resolves the issue.
Who is affected by CVE-2026-12879?
CVE-2026-12879 affects authenticated users of Google Cloud Apigee versions prior to June 12, 2026.
What type of vulnerability is CVE-2026-12879?
CVE-2026-12879 is classified as an Improper Input Validation vulnerability.
What can an attacker do with CVE-2026-12879?
An attacker exploiting CVE-2026-12879 can exfiltrate cross-tenant data within Google Cloud Apigee.