Impact
A missing authorization check in the HTTP Connector of Google Cloud Integration Connectors allows an authenticated user to attach an unauthorized service account, thereby taking over a target Google Cloud Project. This flaw enables full control over the project’s resources, with the potential to alter, delete, or exfiltrate any data and services within the project. The weakness is identified as CWE‑863 (Improper Authorization).
Affected Systems
The vulnerability affects Google Cloud Integration Connectors with versions prior to 2025‑12‑11 on the Google Cloud Platform. Any project that deploys the HTTP Connector before this release date is impacted.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as high severity. While no EPSS score is currently available, the lack of platform‑wide exploit indications and the fact that the vulnerability requires an authenticated user suggest moderate likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker must possess valid credentials and the ability to access the connector to exploit the missing authorization, which then allows them to attach a service account in the project’s context and gain full project‑level privileges.
OpenCVE Enrichment