External risk intelligence

Google Cloud Integration QueryEngineTask Missing Authorization Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-12710

The vulnerability affects Google Cloud Application Integration, a managed cloud service. Such services often expose API endpoints or web interfaces to facilitate integration tasks, making the vulnerable QueryEngineTask plausibly reachable via the public-facing components of the integration platform in common deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Google Cloud Application Integration's QueryEngineTask could have allowed unauthorized access to sensitive internal data. This issue has been addressed.

  • Unauthorized data access was possible.
  • Confirming relevance and exposure is the main concern.
  • Understand potential impact to internal data access.

Attack Path

How an attacker could exploit the issue

An attacker could reach sensitive internal data by interacting with the QueryEngineTask component of Google Cloud Application Integration. This could occur without any authentication or prior access, as the vulnerability allows external access to information that should be protected.

  • No authentication or prior access required.
  • Triggered by interacting with QueryEngineTask.
  • Risk of accessing sensitive internal data.

Live Threat

Current exploitation, exposure, and threat context

A missing authorization vulnerability in Google Cloud Application Integration's QueryEngineTask could allow an external attacker to access sensitive internal data. This exposure could occur when the vulnerable component is reachable by an unauthenticated user.

  • Internal Google Cloud data.
  • Unauthenticated access to sensitive data.
  • Unauthorized internal data disclosure.

Operational Fix

Recommended remediation, mitigation, and detection steps

No customer action is required for this vulnerability as it has been patched. The Google Cloud Application Integration platform manages the affected components, and the vendor has released a fix. Teams should monitor vendor advisories for future updates and maintain awareness of their deployment's configuration.

  • Ownership: Google Cloud Platform (vendor)
  • Verify first: No customer action required.
  • Action: Monitor vendor communications.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Cloud Application Integration?

It is a cloud-based service that enables users to connect different applications, data, and services within a unified environment. By managing workflows and data orchestration, it acts as a bridge between various software components, allowing them to communicate and share information automatically.

What does CWE-862 mean for CVE-2026-12710?

CWE-862 refers to a 'Missing Authorization' weakness. In simple terms, the software failed to verify if a user had permission to perform an action. For this specific vulnerability, the QueryEngineTask component did not check for authorization, which allowed unauthorized users to view sensitive data that should have been restricted.

How is the QueryEngineTask vulnerability triggered?

An attacker triggers this by interacting with the QueryEngineTask component through the network. Because the system lacked proper access checks, the vulnerability is triggered by direct requests to the component. It is not triggered by standard, authorized workflows that already have valid credentials applied to the task.

Is my environment at risk according to Halo Surface Signal?

Halo Surface Signal indicates this is a likely risk for many users because Google Cloud Application Integration is a managed service that often exposes API endpoints or web interfaces to the internet. Since these components facilitate integration tasks, the vulnerable task is frequently reachable through public-facing interfaces, making it a priority to understand your configuration.

Do I need to patch my Google Cloud Application Integration instance?

No action is required from you. Because this is a managed cloud service, the vendor has already applied the fix to the platform as of April 4, 2026. You do not need to update or modify your own environment, though you should remain aware of vendor security communications.

References