GCP-2026-058
Imported from official source
Published: 2026-09-02Description Description Severity Notes A missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attacker to register an attached cluster into an arbitrary target project's Workload Identity Federation for GKE. …
This version
- Version
- 1 of 4
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
804e8602382a684ca36619d78fe53f96- All versions
- Revision history