PT-2026-82091 · Cdata+1 · Cdata Jdbc Driver+1
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear |
Name of the Vulnerable Software and Affected Versions
Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01
Description
Improper input validation in the CData JDBC driver integration allows an authenticated attacker to achieve remote code execution within the connector container. By using crafted JDBC connection string parameters, the attacker can also escalate privileges in the tenant project.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bigquery Data Transfer Service
Cdata Jdbc Driver