A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import.


This vulnerability was patched on 15 March 2026, and no customer action is needed.

Project Subscriptions

Vendors Products
Cloud Dialogflow Cx Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 11 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Dialogflow Cx
Vendors & Products Google
Google cloud Dialogflow Cx

Thu, 11 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. This vulnerability was patched on 15 March 2026, and no customer action is needed.
Title Privilege Escalation in Dialogflow CX via Playbook Import
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-06-11T12:41:05.278Z

Reserved: 2026-03-24T11:41:11.276Z

Link: CVE-2026-4764

cve-icon Vulnrichment

Updated: 2026-06-11T12:41:00.624Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-11T12:16:31.620

Modified: 2026-06-11T15:22:48.573

Link: CVE-2026-4764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T12:30:14Z

Weaknesses