{"id":"CVE-2026-4644","title":"A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project…","summary":"A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project…","severity":"none","cwe":["CWE-863"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:16:31.017","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4644","references":[{"url":"https://docs.cloud.google.com/support/bulletins#gcp-2026-059","label":"f45cbf4e-4146-4068-b7e1-655ffc2c548c"}],"tags":["nvd"],"epss":0.00226,"epssPercentile":0.13574,"ingestedAt":"2026-09-08T15:33:26.960Z","slug":"CVE-2026-4644","body":"## Overview\n\nA Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.\n\n\n\nThis vulnerability was patched on 11 December 2025, and no customer action is needed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}