Executive brief
Google Cloud Integration Connectors is a managed service that allows secure connections between applications and APIs. A missing authorization check in the HTTP Connector could allow an authenticated attacker to escalate privileges by using an unauthorized service account attachment, potentially leading to complete compromise of a Google Cloud project.
Technical details
A missing authorization vulnerability exists in the HTTP Connector component of Google Cloud Integration Connectors versions prior to December 11, 2025. The vulnerability allows an authenticated attacker to attach and use an unauthorized service account, bypassing authorization checks. This enables privilege escalation and project takeover. The vulnerability was patched on December 11, 2025, and the advisory indicates no customer action is required as all customers have been updated.
Affected products
- Google Cloud Integration Connectors prior to December 11, 2025
Timeline
- 2025-12-11: patched
- 2026-09-04: disclosed