PT-2025-50307 · Google Cloud · Dialogflow Cx

Asterfiester

·

Published

2025-12-10

·

Updated

2025-12-10

·

CVE-2025-12952

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Name of the Vulnerable Software and Affected Versions Google Cloud Dialogflow CX (affected versions not specified)
Description A privilege escalation issue exists in Google Cloud's Dialogflow CX. Developers with Webhook editor permission can configure Webhooks using Dialogflow service agent access token authentication. This allows an attacker to escalate privileges from agent-level to project-level, gaining unauthorized access to manage project resources, potentially leading to unexpected costs and resource depletion. The issue involves the use of Dialogflow service agent access tokens for Webhook authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-12952

Affected Products

Dialogflow Cx