GCP-2026-048
Imported from official source
Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets. For instructions and more details, see the Developer Connect security bulletin. Medium
This version
- Version
- 1 of 3
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
942abbeb177aa9e22357baaaeb862367- All versions
- Revision history