PatchSiren cyber security CVE debrief
CVE-2026-4764 Google Cloud CVE debrief
CVE-2026-4764 is a Critical Missing Authorization vulnerability in Dialogflow CX on Google Cloud Platform. An authenticated user with specific roles can exploit this vulnerability to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. The vulnerability was patched on March 15, 2026, and no customer action is required.
- Vendor
- Google Cloud
- Product
- Dialogflow CX
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-11
- Original CVE updated
- 2026-06-11
- Advisory published
- 2026-06-11
- Advisory updated
- 2026-06-11
Who should care
Users of Dialogflow CX on Google Cloud Platform, especially those with specific roles that could be exploited for privilege escalation.
Technical summary
The vulnerability has a CVSS score of 9.4 and is classified as CRITICAL. It allows an attacker to escalate privileges and potentially take over a GCP project. The vulnerability was patched on March 15, 2026.
Defensive priority
high
Recommended defensive actions
- Review the patch notes for Dialogflow CX on Google Cloud Platform to ensure the patch has been applied.
- Monitor user activity and privilege escalation attempts in your GCP projects.
- Restrict roles and permissions for users who could potentially exploit this vulnerability.
Evidence notes
The vendor is listed as Unknown Vendor, but evidence suggests the vulnerability is related to Google.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://docs.cloud.google.com/dialogflow/docs/release-notes
f45cbf4e-4146-4068-b7e1-655ffc2c548c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.