Skip to content
Google CloudCVE-2026-4644

Google Cloud Integration Connectors: missing authorization

High8.5CVE-2026-4644 · Published Sep 4, 2026 · updated Sep 8, 2026

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.

Google Cloud advisory

Affected versions

PackageAffectedFixed in
Integration Connectors
Product
< 2025-12-112025-12-11
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Clear
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Google Cloud advisories

All Google Cloud
Advisory
Google Cloud Gemini Enterprise: server-side request forgery
High8.7Sep 11
Google Cloud Gemini CLI: code execution
High7.7Sep 10
Google Cloud Agent Development Kit (ADK) for Python: code injection
Critical10.0Sep 9
Google Cloud Agent Development Kit (ADK): path traversal
High8.7Sep 4
Google Cloud Build: improper authorization
Critical9.4Aug 31
Google Cloud Vertex AI Search for Commerce: weak randomness
Critical9.3Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.