CVE Explorer
CVE-2026-3259
A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism in Google BigQuery on Google Cloud Platform allows an authenticated user to potentially disclose sensitive data using a crafted materialized view that triggers a runtime error during the refresh process.
This vulnerability was patched on 29 January 2026, and no customer action is needed.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"BigQuery","vendor":"Google Cloud","versions":[{"lessThan":"01/29/2026","status":"affected","version":"0","versionType":"date"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a9436672436a96e20c047941c86c7a997b3e6e5dbc39fce36a423bc79876cb53 · sha256:21225763423ac68f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"CLEAR","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/U:Clear","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a9436672436a96e20c047941c86c7a997b3e6e5dbc39fce36a423bc79876cb53 · sha256:21225763423ac68f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-209","description":"CWE-209 Generation of error message containing sensitive information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a9436672436a96e20c047941c86c7a997b3e6e5dbc39fce36a423bc79876cb53 · sha256:21225763423ac68f… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://docs.cloud.google.com/bigquery/docs/release-notes/#April_15_2026"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a9436672436a96e20c047941c86c7a997b3e6e5dbc39fce36a423bc79876cb53 · sha256:21225763423ac68f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.