gcp Google Cloud release notes ·

BigQuery Data Transfer Service JDBC Driver Security Vulnerability

securitygcpsecurity-advisoryengineergcp-bigquery
security

An improper input validation vulnerability has been identified in the JDBC driver for BigQuery Data Transfer Service versions prior to May 1, 2026. This flaw could allow an authenticated attacker to execute remote code within the connector container. Exploiting this vulnerability could also lead to privilege escalation within the tenant project. For detailed information, users should consult the GCP-2026-056 security bulletin.

Security (1)
  • BigQuery

    An Improper Input Validation vulnerability was discovered in the JDBC driver in BigQuery Data Transfer Service versions prior to May 1, 2026. An authenticated attacker could use crafted JDBC connection string parameters to achieve remote code execution in the connector container and escalate privileges in the tenant project. For more information, see the GCP-2026-056 security bulletin.

Read the original announcement →

https://docs.cloud.google.com/release-notes#August_26_2026

Related releases