CVE-2026-4764 CRITICAL

CVE-2026-4764: Privilege Escalation in Dialogflow CX via Playbook Import

Vendor Google Cloud
Product Dialogflow CX
Weakness CWE-862 · Missing authorization
Published June 11, 2026
Last update June 11, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear

What the vulnerability does

01Description

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. This vulnerability was patched on 15 March 2026, and no customer action is needed.

Key dates

02Disclosure timeline

June 11, 2026 CVE published
June 11, 2026 Record updated