CVE-2026-3259 is an information disclosure vulnerability in Google BigQuery's Materialized View Refresh mechanism that allows authenticated users to extract sensitive data by crafting a materialized view designed to trigger runtime errors during the refresh process. The vulnerability affects Google Cloud Platform users leveraging the BigQuery service. The attack requires valid authentication credentials and moderate complexity to exploit, as it necessitates the creation of a specifically engineered materialized view to generate error messages containing sensitive information. The primary risk is unauthorized disclosure of confidential data that may be revealed in error output, though the attack surface is limited to authenticated users with appropriate BigQuery access. There is no evidence of active exploitation or public exploit code availability. The vulnerability has not been designated for the Known Exploited Vulnerabilities catalog, and community attention appears minimal. Google patched this issue on January 29, 2026, with no required customer remediation, indicating the fix was implemented transparently on the service side.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Google Cloud | BigQuery | >= 0, < 01/29/2026CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.