SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-4644

HIGH · CVSS 8.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A missing authorization vulnerability in the HTTP Connector of Google Cloud Integration Connectors allows authenticated users to escalate privileges and potentially take control of a Google Cloud Project by attaching unauthorized service accounts. Organizations using affected versions prior to December 11, 2025, should prioritize this issue to prevent unauthorized access and potential data breaches. However, since the vulnerability has been patched, no immediate action is required from customers.

CVE
CVE-2026-4644
Severity
HIGH
CVSS
8.5
EPSS
0.23%

Original NVD Description

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on 11 December 2025, and no customer action is needed.