BigQuery Data Transfer Service JDBC Driver Security Vulnerability
An improper input validation vulnerability has been identified in the JDBC driver for BigQuery Data Transfer Service versions prior to May 1, 2026. This flaw could allow an authenticated attacker to execute remote code within the connector container. Exploiting this vulnerability could also lead to privilege escalation within the tenant project. For detailed information, users should consult the GCP-2026-056 security bulletin.
Security (1) ›
- BigQuery
An Improper Input Validation vulnerability was discovered in the JDBC driver in BigQuery Data Transfer Service versions prior to May 1, 2026. An authenticated attacker could use crafted JDBC connection string parameters to achieve remote code execution in the connector container and escalate privileges in the tenant project. For more information, see the GCP-2026-056 security bulletin.
https://docs.cloud.google.com/release-notes#August_26_2026
Related releases
- Terraform Google Provider v8.0.0 introduces significant breaking changes Terraform Google Provider Releases ·
- Google Cloud enhances Knowledge Catalog for managing Open Knowledge Format (OKF) bundles Google Cloud Blog ·
- BigQuery Data Governance Tags Now Supported in Terraform Google Cloud release notes ·
- BigQuery Integrates Google Cloud Observability for Data Agent Monitoring Google Cloud release notes ·
- BigQuery Adds Time Series ML Functions, Deprecates Graph in Standard, and Enhances AI Agent CLI Access Google Cloud release notes ·
- Google Cloud details Hive Metastore modernization with Lakehouse runtime catalog Google Cloud Blog ·