Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-12952

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-269 Gestión de privilegios incorrecta
Fecha de publicación:
10/12/2025
Última modificación:
12/12/2025

Descripción

*** Pendiente de traducción *** A privilege escalation vulnerability exists in Google Cloud&amp;#39;s Dialogflow CX.<br /> <br /> Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. <br /> This allows the attacker to escalate their privileges from agent-level to project-level, granting them unauthorized access to manage resources in services associated with the project, leading to unexpected costs and resource depletion for the producer project.<br /> <br /> A fix was applied on the server side to protect from this vulnerability in February 2025. No customer action is required.

Referencias a soluciones, herramientas e información