SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-14934

CRITICAL · CVSS 9.4 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the repository creation functionality of Google Cloud BigQuery, Dataform, and Colab Enterprise allows authenticated attackers to escalate privileges and potentially take over repositories across different tenants. Organizations using these services between October 2025 and May 10, 2026, should prioritize reviewing their access controls and ensuring they are on the patched version, although no immediate customer action is required as the issue has been resolved.

CVE
CVE-2026-14934
Severity
CRITICAL
CVSS
9.4
EPSS
0.23%

Original NVD Description

A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and perform cross-tenant repository takeover. This vulnerability was patched on 10 May 2026, and no customer action is needed.