{"id":"CVE-2026-4644","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-4644","summary":"A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to…","details":"A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.\n\n\n\nThis vulnerability was patched on 11 December 2025, and no customer action is needed.","published":"2026-09-04T11:17:18.830","modified":"2026-09-04T11:17:18.830","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://docs.cloud.google.com/support/bulletins#gcp-2026-059"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T11:17:18.830"}}