Dataform Security Vulnerability in BigQuery and Colab Enterprise
datasecuritygcpengineergcp-bigquery
security
A security vulnerability was found in Dataform repositories within BigQuery and Colab Enterprise, allowing authenticated attackers to escalate privileges and take over cross-tenant repositories. This impacts users of Dataform, BigQuery, and Colab Enterprise. Further details are available in the GCP-2026-047 security bulletin.
Security (1) ›
- Dataform
A Missing Authorization vulnerability was discovered in repositories in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could potentially escalate permissions and perform cross-tenant repository takeover. For more information, see the GCP-2026-047 Dataform security bulletin.
Read the original announcement →
https://docs.cloud.google.com/release-notes#July_13_2026
Related releases
- Google Cloud AI Infrastructure and Orchestration Updates - July 2026 Google Cloud Blog ·
- Data Studio Conversational Analytics GA, adds BigQuery integration Google Cloud release notes ·
- Cortex Framework v7 GA with modular architecture, Dataform, and AI features Google Cloud release notes ·
- BigQuery: Audit UI query result downloads Google Cloud release notes ·
- BigQuery Data Transfer Service adds incremental Klaviyo transfers Google Cloud release notes ·
- Google Cloud Announces Borderless Lakehouse for Cross-Cloud Data Access Google Cloud Blog ·