CVE-2025-12952
Severity CVSS v4.0:
HIGH
Type:
CWE-269
Improper Privilege Management
Publication date:
10/12/2025
Last modified:
12/12/2025
Description
A privilege escalation vulnerability exists in Google Cloud&#39;s Dialogflow CX.<br />
<br />
Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. <br />
This allows the attacker to escalate their privileges from agent-level to project-level, granting them unauthorized access to manage resources in services associated with the project, leading to unexpected costs and resource depletion for the producer project.<br />
<br />
A fix was applied on the server side to protect from this vulnerability in February 2025. No customer action is required.



