CVE-2026-4644
—Privilege Escalation via Missing Authorization in Google Cloud Integration Connectors
A missing authorization flaw (CWE-863) in the HTTP Connector component of Google Cloud Integration Connectors on Google Cloud Platform, in versions prior to the 2025-12-11 release, lets an authenticated user attach an unauthorized service account. Through this unauthorized attachment, the user escalates privileges and can take over the targeted Google Cloud Project, with high impact on the project's system confidentiality and integrity per the CVSS 4.0 score of 8.5. Only GCP customers using Integration Connectors with versions before 2025-12-11 are affected. Google patched the managed service on 11 December 2025 and states no customer action is needed; there is no known exploitation, no public proof-of-concept, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: No upgrade is required because this is a Google-managed service that Google patched server-side on 2025-12-11, but verify your projects' Integration Connectors are on the current version and review Cloud Audit Logs for unexpected service account attachments or IAM grant changes by authenticated users. As a precaution, restrict which identities can invoke HTTP Connector operations and audit service accounts in your projects for unusual key usage or new grants.
| Google Integration Connectors (HTTP Connector) on Google Cloud Platform | all versions prior to 2025-12-11 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.
- Weakness
- CWE-863
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
In the news0 stories
No ingested article mentions this CVE yet.