CVE-2025-12952 - CVE House
Back to Database
Status published High CVE-2025-12952

Privilege Escalation in Dialogflow CX via Webhook Admin Role

Vulnerability Description

A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. This allows the attacker to escalate their privileges from agent-level to project-level, granting them unauthorized access to manage resources in services associated with the project, leading to unexpected costs and resource depletion for the producer project. A fix was applied on the server side to protect from this vulnerability in February 2025. No customer action is required.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12952

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • asterfiester

Affected Vendor

Google Cloud

View all reports →

Affected Software

Dialogflow CX
Vulnerable Versions:
0

Timeline

Official Publish: December 10th, 2025
Last Modified: December 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)