CVE-2026-4644

8.5

Google · Integration Connectors

A missing authorization vulnerability in the Google Cloud Integration Connectors HTTP Connector allows authenticated users to escalate privileges and compromise Google Cloud Projects.

Executive summary

An authenticated user can escalate privileges and take over a Google Cloud Project due to a missing authorization vulnerability in the Google Cloud Integration Connectors HTTP Connector.

Vulnerability

This vulnerability is classified as an incorrect authorization flaw (CWE-863) within the HTTP Connector. The flaw permits an authenticated user to perform unauthorized actions, specifically attaching service accounts to gain elevated control over a Google Cloud Project.

Business impact

The ability for an authenticated user to escalate privileges and seize control of a Google Cloud Project represents a severe risk to organizational infrastructure. With a CVSS score of 8.5, this vulnerability could lead to total compromise of data, unauthorized resource manipulation, and potential exfiltration of sensitive information across the cloud environment.

Remediation

Immediate Action: No customer action is required as Google has confirmed the vulnerability was patched on the backend on December 11, 2025.

Proactive Monitoring: Review Google Cloud Platform audit logs for suspicious service account attachments or unauthorized modifications to project configurations.

Compensating Controls: Ensure the principle of least privilege is applied to all service accounts and utilize Google Cloud IAM conditions to restrict access to sensitive connector configurations.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

While no immediate patching is required by the user, security teams should verify that their internal security policies align with the updated authorization controls enforced by Google. Organizations should continue to enforce strict identity and access management practices to limit the blast radius of any potential account-level compromise.

More Google CVEs

Sources

Originally found and disclosed by asterfiester, per the CVE Program record.