{"id":"CVE-2026-12710","title":"A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.\n\n\n\n\nThe issue was patched on Apr…","summary":"A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.\n\n\n\n\nThe issue was patched on Apr…","severity":"none","cwe":["CWE-862"],"published":"2026-08-22","updated":"2026-08-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12710","references":[{"url":"https://cloud.google.com/application-integration/docs/release-notes#August_21_2026","label":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"}],"tags":["nvd"],"epss":0.00406,"epssPercentile":0.32107,"ingestedAt":"2026-08-23T04:42:13.390Z","slug":"CVE-2026-12710","body":"## Overview\n\nA Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data.\n\n\n\n\nThe issue was patched on April 4, 2026; no customer action is required.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}