Back

HIGH

Improper Authorization in Google Cloud Integration Connectors Leads to Project Takeover

Published Sep 4, 2026

Description

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment.

This vulnerability was patched on 11 December 2025, and no customer action is needed.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GoogleCloud
Published Sep 4, 2026
Updated Sep 4, 2026
Reserved Mar 23, 2026
CISA Vulnrichment
Updated Sep 4, 2026
NVD
Status Awaiting Analysis
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GoogleCloud
Published Sep 4, 2026
Updated Sep 4, 2026
Exploited since n/a
EUVD-2026-70996