Security Advisory Desk
unratedQCS priority 70/100Google Cloud

GCP-2026-059

A security flaw was found in the HTTP Connector of Google Cloud's Integration Connectors software before December 11, 2025. This flaw could let someone with a user account improperly attach a service account and gain higher rights, potentially taking control of a Google Cloud project. Google fixed this issue on December 11, 2025, and customers don't need to take any action.

Published 4/9/2026, 9:52:42 amVerified 4/9/2026, 11:06:55 amRevision 1
Google Cloud unrated network security advisory visual

In plain language

What this advisory means

A security flaw was found in the HTTP Connector of Google Cloud's Integration Connectors software before December 11, 2025. This flaw could let someone with a user account improperly attach a service account and gain higher rights, potentially taking control of a Google Cloud project. Google fixed this issue on December 11, 2025, and customers don't need to take any action.

Technical explanation

How the issue affects the environment

The vulnerability is a missing authorization check in the HTTP Connector component within Google Cloud's Integration Connectors prior to the December 11, 2025 patch. An authenticated attacker could exploit this to attach an unauthorized service account, thereby escalating privileges and potentially achieving full takeover of a Google Cloud project. This flaw allows privilege escalation by leveraging improper verification when attaching service accounts, bypassing intended access controls.

Operational impact

Why teams should care

If exploited, an attacker with some authenticated access could escalate their privileges to gain control over an entire Google Cloud project. This could lead to unauthorized access to resources, data breaches, and disruption of cloud services managed within the project, impacting business operations and data security.

Immediate action

Google patched the vulnerability in the Integration Connectors as of December 11, 2025. Customers running affected versions should ensure their systems are updated to versions released on or after this date to receive the fix.

Affected and fixed releases

Affected versionsIntegration Connectors versions prior to December 11, 2025
Fixed versionsVersions of Integration Connectors released on or after December 11, 2025

Temporary risk reduction

No customer action or workaround is required as Google has already applied the patch to affected systems. Users should confirm they are running updated versions.

Evidence and validation checklist

  • Official Google Cloud Security Bulletin GCP-2026-059
  • Reference to CVE-2026-4644
  • Date of patch release: December 11, 2025
  • Description of vulnerability as missing authorization in HTTP Connector
  • Impact as privilege escalation and project takeover

Authoritative reference

Google Cloud Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source