The issue was patched on April 4, 2026; no customer action is required.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Access is now restricted and the issue is resolved. Integrations using QueryEngineTask for external traffic will return a PERMISSION_DENIED error. We recommend that customers remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks in their Application Integration workflows.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 22 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required. | |
| Title | Missing Authorization in Application Integration QueryEngineTask | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-08-22T08:13:00.095Z
Reserved: 2026-06-19T10:49:27.988Z
Link: CVE-2026-12710
No data.
Status : Received
Published: 2026-08-22T09:16:53.340
Modified: 2026-08-22T09:16:53.340
Link: CVE-2026-12710
No data.
OpenCVE Enrichment
Updated: 2026-08-22T10:45:03Z