VDB

GCVE-110-CLOUD-2020-0003

GCVE-110-CLOUD-2020-0003
Advisory Published
Vulnetix · Advisory published November 22, 2020
When the compute API is enabled on a GCP Project, the default compute account is created. This account gets the primitive role Editor assigned by default, which allows for a wide variety of privilege excalation and resource abuse in the project. Especially, all new VMs created inherit this permissions by default. This issue is arguably a technical decision by GCP, but the documents advise customers to undo this.

Affected Products

VendorProductVersionsPlatforms
GCPCloud Services

References

advisory

Browse GCVE Records

74,366 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›