SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84962

MEDIUM · CVSS 4.2 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthorized user with write access to a key vault can exploit this vulnerability to make arbitrary authenticated calls to the Google Cloud KMS API, effectively impersonating an authorized user. This could lead to unauthorized access to sensitive data and compromise client-side encryption mechanisms. Organizations utilizing Google Cloud services with key vault configurations should prioritize addressing this issue to safeguard their data integrity and confidentiality.

CVE
CVE-2026-84962
Severity
MEDIUM
CVSS
4.2
EPSS
0.12%

Original NVD Description

An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.