GCP-2026-048
Imported from official source
Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets. For instructions and more details, see the Developer Connect security bulletin. Medium
This version
- Version
- 2 of 3
- Recorded
- September 25, 2026 09:00
- Change
- Imported change
- Content hash
a1f4069ab4b14006488f12459a9f4e9b- All versions
- Revision history