---
id: CVE-2026-4644
title: >-
  A Missing Authorization vulnerability in HTTP Connector in Google Cloud
  Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform
  allows an authenticated user to escalate privileges and take over a Google
  Cloud Project…
summary: >-
  A Missing Authorization vulnerability in HTTP Connector in Google Cloud
  Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform
  allows an authenticated user to escalate privileges and take over a Google
  Cloud Project…
severity: none
cwe:
  - CWE-863
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:16:31.017'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4644'
references:
  - url: 'https://docs.cloud.google.com/support/bulletins#gcp-2026-059'
    label: f45cbf4e-4146-4068-b7e1-655ffc2c548c
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.13588
ingestedAt: '2026-09-08T15:33:26.960Z'
---

## Overview

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.



This vulnerability was patched on 11 December 2025, and no customer action is needed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
