In plain language
What this advisory means
Google Cloud identified a security problem in the BigQuery Data Transfer Service's JDBC driver before May 1, 2026. This issue allowed attackers with valid credentials to craft special connection strings that could let them run harmful code and gain higher privileges in a customer project. Google fixed this problem on May 1, 2026. Customers do not need to take any action.
Technical explanation
How the issue affects the environment
An authenticated attacker could exploit an improper input validation flaw in the JDBC driver within BigQuery Data Transfer Service (versions prior to May 1, 2026). By crafting malicious JDBC connection string parameters, the attacker could achieve remote code execution within the connector container, resulting in privilege escalation inside the tenant project. This vulnerability permits an attacker to execute arbitrary code with escalated privileges, breaching tenant isolation. The issue was patched by Google on May 1, 2026, eliminating the improper validation in the JDBC driver.
Operational impact
Why teams should care
This vulnerability critically undermined the security boundary of the BigQuery Data Transfer Service by enabling authenticated attackers to execute arbitrary code remotely and escalate privileges within customer projects. Such attacks could result in data breaches, unauthorized access to sensitive information, and disruption of cloud services. However, since the patch has been deployed and no customer action is required, the risk is currently mitigated.
Immediate action
Google Cloud has patched the vulnerability in the JDBC driver for BigQuery Data Transfer Service as of May 1, 2026. No customer intervention is necessary to remediate this issue.
Affected and fixed releases
Temporary risk reduction
The official source does not specify any workaround, and no customer action is needed since the fix is already applied by Google.
Evidence and validation checklist
- Google Cloud Security Bulletins - GCP-2026-056
- Advisory publication date: 2026-08-26
- Description of improper input validation in JDBC driver
- CVE-2026-12717 assigned
- Patch applied on May 1, 2026
- No customer action required
Authoritative reference
Google Cloud Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
