CVE-2026-12715: Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and acc
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.
This vulnerability was patched on 15 April 2026, and no customer action is needed.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-12715
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-127150.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12715 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Missing Authorization in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-15227: Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an au…nvd · 2026-07-31
- highCVE-2026-15397: The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization …nvd · 2026-07-30
- unknownCVE-2026-66724: MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the de…nvd · 2026-07-29
- unknownCVE-2026-66723: MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Re…nvd · 2026-07-29
- criticalCVE-2026-14488: The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_…nvd · 2026-07-29
- highCVE-2026-50622: Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in A…nvd · 2026-07-29
More from NVD Recent CVEs
- unknownCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…2026-08-01
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01