GCP-2026-058
Imported from official source
Published: 2026-09-02Description Description Severity Notes A missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attacker to register an attached cluster into an arbitrary target project's Workload Identity Federation for GKE. …
This version
- Version
- 3 of 4
- Recorded
- September 25, 2026 09:00
- Change
- Imported change
- Content hash
f804b528993a9b405ad037ffadde53d5- All versions
- Revision history