Description
A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.



This vulnerability was patched on 11 December 2025, and no customer action is needed.
Published: 2026-09-04
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the HTTP Connector of Google Cloud Integration Connectors allows an authenticated user to attach an unauthorized service account, thereby taking over a target Google Cloud Project. This flaw enables full control over the project’s resources, with the potential to alter, delete, or exfiltrate any data and services within the project. The weakness is identified as CWE‑863 (Improper Authorization).

Affected Systems

The vulnerability affects Google Cloud Integration Connectors with versions prior to 2025‑12‑11 on the Google Cloud Platform. Any project that deploys the HTTP Connector before this release date is impacted.

Risk and Exploitability

The CVSS score of 8.5 classifies this flaw as high severity. While no EPSS score is currently available, the lack of platform‑wide exploit indications and the fact that the vulnerability requires an authenticated user suggest moderate likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker must possess valid credentials and the ability to access the connector to exploit the missing authorization, which then allows them to attach a service account in the project’s context and gain full project‑level privileges.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Confirm that the Integration Connector is upgraded to version 2025‑12‑11 or later.
  • Ensure that any service accounts used by connectors are granted only the minimal IAM roles required for operation.
  • Regularly review Cloud Audit logs for unauthorized service account attachments or privileged actions.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
Title Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-09-04T10:19:13.421Z

Reserved: 2026-03-23T12:12:25.063Z

Link: CVE-2026-4644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T11:17:18.830

Modified: 2026-09-04T11:17:18.830

Link: CVE-2026-4644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T11:30:17Z

Weaknesses