Junglewise Threat Intelligence

CVE-2026-4764: Google Cloud Dialogflow CX privilege escalation in playbook import

CVE-2026-4764 · Severity: info · CVSS 9.4 · Published 2026-06-11

Vendors: Google.

Executive brief

A security vulnerability in Google Cloud's Dialogflow CX, a platform for building conversational AI, could have allowed certain authorized users to gain excessive permissions. By importing a specially crafted 'playbook,' an attacker could have potentially taken full control over a Google Cloud project. This could lead to unauthorized access to sensitive data or the disruption of cloud services. Google has already patched the issue, and no action is required from customers.

Technical details

A missing authorization vulnerability (CWE-862) existed in the playbook import functionality of Dialogflow CX on Google Cloud Platform. The flaw allowed an authenticated user with specific low-privileged roles to bypass intended access controls by importing a maliciously crafted playbook. Successful exploitation could lead to full privilege escalation and project takeover. The vulnerability was identified as a server-side authorization failure during the import process. Google patched the vulnerability on March 15, 2026, by implementing proper authorization checks on the playbook import endpoint.

Affected products

  • Google Cloud Platform Dialogflow CX

Timeline

  • 2026-03-15: patched: Vulnerability was patched by Google; no customer action required.
  • 2026-06-11: advisory: CVE published to NVD.

References