CVE-2026-4644
Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
| CWE | CWE-863 |
| Vendor | google cloud |
| Product | integration connectors |
| Published | Sep 4, 2026 |
| Last Updated | Sep 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud integration connectors
Be the first to know when new unknown vulnerabilities affecting google cloud integration connectors are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Integration Connectors
0 < 2025-12-11
References
Credits
๐ asterfiester