GCP-2026-048MediumDisclosed before NVD
GCP-2026-048 — Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect.
📋 Description
Published: 2026-07-13Description Description Severity Notes A privilege escalation vulnerability was addressed in Developer Connect. Previously, for GitLab Enterprise and Bitbucket Data Center connections, when Secret Manager secrets were retrieved, permissions were checked against the Developer Connect service agent (P4SA) credentials only. Developer Connect now validates that both the calling principal and the P4SA have the required permissions on the referenced secrets. For instructions and more details, see the Developer Connect security bulletin. Medium