This vulnerability was patched on 11 December 2025, and no customer action is needed.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://docs.cloud.google.com/support/bulletins#gcp-2026-059 |
|
Fri, 04 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google Cloud
Google Cloud integration Connectors |
|
| Vendors & Products |
Google Cloud
Google Cloud integration Connectors |
Fri, 04 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed. | |
| Title | Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-04T16:09:28.967Z
Reserved: 2026-03-23T12:12:25.063Z
Link: CVE-2026-4644
Updated: 2026-09-04T16:09:23.433Z
Status : Received
Published: 2026-09-04T11:17:18.830
Modified: 2026-09-04T16:17:25.417
Link: CVE-2026-4644
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:20:09Z