CVE-2026-4644

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 11:17

Updated : 2026-09-08 14:16


NVD link : CVE-2026-4644

Mitre link : CVE-2026-4644

CVE.ORG link : CVE-2026-4644


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization