GCP-2026-048MediumDisclosed before NVD

GCP-2026-048 — Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect.

Published
July 13, 2026
Last Modified

📋 Description

Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets. For instructions and more details, see the Developer Connect security bulletin. Medium

🔗 References (1)