GCP-2026-058
Imported from official source
Published: 2026-09-02Description Description Severity Notes A missing project permission check in GKE Multi-Cloud (CreateAttachedCluster, CreateAwsCluster, CreateAzureCluster) APIs allowed an attacker to register an attached cluster into an arbitrary target project's Workload Identity Federation for GKE. …
This version
- Version
- 4 of 4
- Recorded
- September 28, 2026 11:00
- Change
- Imported change
- Content hash
2d089976671bcb10690b8575c8cd5c00- All versions
- Revision history