This vulnerability was patched on 11 December 2025, and no customer action is needed.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://docs.cloud.google.com/support/bulletins#gcp-2026-059 |
|
Fri, 04 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed. | |
| Title | Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-09-04T10:19:13.421Z
Reserved: 2026-03-23T12:12:25.063Z
Link: CVE-2026-4644
No data.
Status : Received
Published: 2026-09-04T11:17:18.830
Modified: 2026-09-04T11:17:18.830
Link: CVE-2026-4644
No data.
OpenCVE Enrichment
Updated: 2026-09-04T11:30:17Z