top of page
perceptive_background_267k.jpg

Google Cloud Platform (GCP) Cloud Monitoring Cross-Tenant BigQuery Leak with Custom Dashboard

Published:

28 januari 2026 om 16:14:08

Alert date:

28 januari 2026 om 17:01:17

Source:

tenable.com

Click to open the original link from this advisory

Cloud & Virtualization, Data Breach & Exfiltration

Tenable Research disclosed a data exfiltration vulnerability in Google Cloud Monitoring that allowed attackers to leak sensitive data from victim's BigQuery datasets. The flaw abused Observability Analytics widgets in custom dashboards that executed with viewer's permissions. Attackers could create malicious SQL queries in dashboard widgets that raised errors containing victim's private BigQuery data, which would be exfiltrated to the attacker's project logs when the victim browsed the shared dashboard. The vulnerability required the attacker to grant IAM permissions to the victim in their tenant and trick them into viewing the malicious dashboard.

Technical details

Mitigation steps:

Affected products:

Google Cloud Platform
Google Cloud Monitoring
BigQuery

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page