GCP-2026-058

Imported from official source

Security notice

Cybersecurity Classified by Officially

Published: 2026-09-02

Description

Description Severity Notes

A missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attacker to register an attached cluster into an arbitrary target project's Workload Identity Federation for GKE. This registration allowed unauthorized creation of Workload Identity tokens and impersonation of Kubernetes Service Accounts that have bindings in the target project through the Workload Identity Federation for GKE configuration.

For instructions and more details, see the GKE security bulletin

This is an extract. The publication continues at the source.

Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-058

Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

4 versions recorded. The original is kept in full — nothing is overwritten.

  1. v4 imported change on current
  2. v3 imported change on
  3. v2 imported change on
  4. v1 as first published on

Provenance

Organization
Google — imported from official source
Official source
https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
Imported
September 15, 2026 20:57
Versions
4 recorded
Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-058

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.