Description
A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.



This vulnerability was patched on 11 December 2025, and no customer action is needed.
Published: 2026-09-04
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation leading to full control of a Google Cloud Project
Action: No action required
AI Analysis

Impact

A missing authorization check in the HTTP Connector of Google Cloud Integration Connectors allows an authenticated user to attach an unauthorized service account, thereby taking over a target Google Cloud Project. This flaw enables full control over the project’s resources, with the potential to alter, delete, or exfiltrate any data and services within the project. The weakness is identified as CWE‑863 (Improper Authorization).

Affected Systems

The vulnerability affects Google Cloud Integration Connectors with versions prior to 2025‑12‑11 on the Google Cloud Platform. Any project that deploys the HTTP Connector before this release date is impacted.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high severity. While no EPSS score is currently available, the lack of platform‑wide exploit indications and the fact that the vulnerability requires an authenticated user suggest moderate likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker must possess valid credentials and the ability to access the connector to exploit the missing authorization, which then allows them to attach a service account in the project’s context and gain full project‑level privileges.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm that the Integration Connector is upgraded to version 2025‑12‑11 or later.
  • Ensure that any service accounts used by connectors are granted only the minimal IAM roles required for operation.
  • Regularly review Cloud Audit logs for unauthorized service account attachments or privileged actions.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud integration Connectors
Vendors & Products Google Cloud
Google Cloud integration Connectors

Fri, 04 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
Title Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

Google Cloud Integration Connectors
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-04T16:09:28.967Z

Reserved: 2026-03-23T12:12:25.063Z

Link: CVE-2026-4644

cve-icon Vulnrichment

Updated: 2026-09-04T16:09:23.433Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T11:17:18.830

Modified: 2026-09-08T14:16:31.017

Link: CVE-2026-4644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:20:09Z

Weaknesses