GCP-2026-048
Imported from official source
Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets. For instructions and more details, see the Developer Connect security bulletin. Medium
This version
- Version
- 3 of 3
- Recorded
- September 28, 2026 11:00
- Change
- Imported change
- Content hash
be78e9ed12d9f65da614235203c63120- All versions
- Revision history