{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-12715",
        "assignerOrgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
        "state": "PUBLISHED",
        "assignerShortName": "GoogleCloud",
        "dateReserved": "2026-06-19T11:04:06.795Z",
        "datePublished": "2026-07-17T15:09:49.401Z",
        "dateUpdated": "2026-07-17T15:28:50.317Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f45cbf4e-4146-4068-b7e1-655ffc2c548c",
                "shortName": "GoogleCloud",
                "dateUpdated": "2026-07-17T15:09:49.401Z"
            },
            "title": "Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-862",
                            "description": "CWE-862 Missing Authorization",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-1",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Google Cloud",
                    "product": "Firebase Studio",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2026-04-15",
                            "versionType": "date"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.\n\n\nThis vulnerability was patched on 15 April 2026, and no customer action is needed.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests.<div><br></div><div>This vulnerability was patched on 15 April 2026, and no customer action is needed.</div>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://docs.cloud.google.com/support/bulletins#gcp-2026-043"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "NONE",
                        "subIntegrityImpact": "HIGH",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "HIGH",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "CLEAR",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.5,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "This vulnerability was patched on April 15, 2026 on the server-side.\n\nAs a precautionary measure, users who may have stored sensitive information such as API keys (e.g., GEMINI_API_KEY) within their Firebase Studio workspace may choose to rotate these keys.\n\nInstructions for rotating the GEMINI_API_KEY can be found at  https://firebase.google.com/docs/studio/troubleshooting#rotate-gemini-key .",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "This vulnerability was patched on April 15, 2026 on the server-side.<br><br>As a precautionary measure, users who may have stored sensitive information such as API keys (e.g., GEMINI_API_KEY) within their Firebase Studio workspace may choose to rotate these keys.<br><br>Instructions for rotating the GEMINI_API_KEY can be found at <a href=\"https://firebase.google.com/docs/studio/troubleshooting#rotate-gemini-key\">https://firebase.google.com/docs/studio/troubleshooting#rotate-gemini-key</a>."
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "A Security Researcher",
                    "type": "reporter"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-07-17T15:28:39.995725Z",
                                "id": "CVE-2026-12715",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-07-17T15:28:50.317Z"
                }
            }
        ]
    }
}