The issue was patched on April 4, 2026; no customer action is required.
Project Subscriptions
No data.
No advisories yet.
Solution
Access is now restricted and the issue is resolved. Integrations using QueryEngineTask for external traffic will return a PERMISSION_DENIED error. We recommend that customers remove or replace any QueryEngineTask (ASIS_TEMPLATE) tasks in their Application Integration workflows.
Workaround
No workaround given by the vendor.
Sat, 22 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required. | |
| Title | Missing Authorization in Application Integration QueryEngineTask | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-08-22T08:13:00.095Z
Reserved: 2026-06-19T10:49:27.988Z
Link: CVE-2026-12710
No data.
Status : Received
Published: 2026-08-22T09:16:53.340
Modified: 2026-08-22T09:16:53.340
Link: CVE-2026-12710
No data.
OpenCVE Enrichment
Updated: 2026-08-22T10:45:03Z