HarborGuard / CVE
Back to search
HIGHCVE-2026-3259Published Modified CNA GoogleCloud

CVE-2026-3259: Sensitive Data Disclosure in BigQuery via Materialized View Error Messages

A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated user to potentially disclose sensitive data using a crafted materialized view that triggers a runtime error during the refresh process. This vulnerability was patched on 29 January 2026, and no customer action is needed.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
01/29/2026
Affected Products
1

Fix available

01/29/2026
Affected packages
  • Google Cloud / BigQuery
    < 01/29/2026 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Clear