GCP-2026-058
Cybersecurity Classified by Officially
Published: 2026-09-02
Description
Description Severity NotesA missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attacker to register an attached cluster into an arbitrary target project's Workload Identity Federation for GKE. This registration allowed unauthorized creation of Workload Identity tokens and impersonation of Kubernetes Service Accounts that have bindings in the target project through the Workload Identity Federation for GKE configuration.
For instructions and more details, see the GKE security bulletin
This is an extract. The publication continues at the source.
Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-058
Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
4 versions recorded. The original is kept in full — nothing is overwritten.
- v4 imported change on current
- v3 imported change on
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- Google — imported from official source
- Official source
- https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
- Imported
- September 15, 2026 20:57
- Versions
- 4 recorded
- Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-058