A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.
This vulnerability was patched on 11 December 2025, and no customer action is needed.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 11:17
Updated : 2026-09-08 14:16
NVD link : CVE-2026-4644
Mitre link : CVE-2026-4644
CVE.ORG link : CVE-2026-4644
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
