CVE-2026-14934: Cross-Tenant Repository Takeover via Improper Access Control in BigQuery, Dataform and Colab Enterprise
A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover.
This vulnerability was patched on 10 May 2026, and no customer action is needed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14934?
CVE-2026-14934 has a critical severity rating of 9.4.
How do I fix CVE-2026-14934?
To fix CVE-2026-14934, ensure proper access control is implemented in the repository creation functionality.
What products are affected by CVE-2026-14934?
CVE-2026-14934 affects Google Cloud BigQuery, Dataform, and Colab Enterprise.
What kind of vulnerability is CVE-2026-14934?
CVE-2026-14934 is a Missing Authorization vulnerability that allows an attacker to escalate privileges.
When was CVE-2026-14934 published?
CVE-2026-14934 was published on July 13, 2026.