NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-7428
Summary

Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database.

Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients blocked it.

Publication Date May 12, 2026, 7:16 p.m.
Registration Date May 13, 2026, 4:11 a.m.
Last Update May 13, 2026, 12:09 a.m.
Related information, measures and tools
Common Vulnerabilities List