Get real-time updates on Telegram
P5Verified
CVE-2025-12405: Looker Studio 0 to before 2025-07-21
CVE-2025-12405. EPSS 0.00256 (percentile 0.15692), scored 2026-10-06.
Affected technology
Looker Studio · 0 to before 2025-07-21
Google Cloud
Component: Not specified by the source
Attack conditions (Source advisory, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report. Source advisory’s CVSS 4.0 assessment (base score 7.7/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-269
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00256 · percentile 0.15692 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-12405.html