๐Ÿ” CVE Alert

CVE-2026-4644

UNKNOWN 0.0

Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.

CWE CWE-863
Vendor google cloud
Product integration connectors
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud integration connectors

Be the first to know when new unknown vulnerabilities affecting google cloud integration connectors are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Integration Connectors
0 < 2025-12-11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-059

Credits

๐Ÿ” asterfiester