A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.



This vulnerability was patched on 11 December 2025, and no customer action is needed.

Project Subscriptions

Vendors Products
Google Cloud Subscribe
Integration Connectors Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud integration Connectors
Vendors & Products Google Cloud
Google Cloud integration Connectors

Fri, 04 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
Title Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-04T16:09:28.967Z

Reserved: 2026-03-23T12:12:25.063Z

Link: CVE-2026-4644

cve-icon Vulnrichment

Updated: 2026-09-04T16:09:23.433Z

cve-icon NVD

Status : Received

Published: 2026-09-04T11:17:18.830

Modified: 2026-09-04T16:17:25.417

Link: CVE-2026-4644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:20:09Z

Weaknesses