CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12715

unknowncovered by 1 sourcefirst seen 2026-07-17
Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is needed.

⚡ Watch CVE-2026-12715

Get an email if CVE-2026-12715 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-12715

CVE.org record

Embed the live status

CVE-2026-12715 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12715 status](https://www.csirts.com/badge/CVE-2026-12715)](https://www.csirts.com/cve/CVE-2026-12715)