CVE-2026-7428 Details
Description
Prior to 2025-11-03, well-intended users of Terraform or REST API for Google Cloud AlloyDB for PostgreSQL could have created clusters with an insecure default password which could have been exploited by a remote attacker to gain full administrative access to the database. Exploitation required network access to the AlloyDB cluster and was limited to Terraform or the REST API, as other clients blocked it.
A vulnerability exists in Google Cloud AlloyDB for PostgreSQL, allowing clusters created prior to November 3, 2025, to have an insecure default password. This default password could be exploited by remote attackers to gain full administrative access to the database. The vulnerability was introduced through the Terraform and REST API, as other clients blocked this behavior. Exploitation required network access to the AlloyDB cluster.
Users can manually set a secure password for the 'postgres' role when creating an AlloyDB cluster. For clusters already created, the password can be updated using the AlloyDB Admin API or the gcloud command-line tool. After updating the password, it's important to review and adjust any application connections that use the old password.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.cloud.google.com/alloydb/docs/release-notes#April_28_2026 | GoogleCloud |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | GoogleCloud |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | GoogleCloud |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | GoogleCloud |