Researcher says Google Cloud Config Connector flaw can bypass IAM and give attackers control of GCP organizations

A researcher says an unpatched flaw in Google Cloud's Config Connector could let a Kubernetes user seize broad control of an organization's Google Cloud environment. The issue, dubbed ConfigConfusion, affects Config Connector, Google's open source Kubernetes add-on for managing cloud resources, and allegedly lets a namespace user abuse a missing authorization check to bypass Identity and Access Management (IAM) and assign owner-level permissions at the Google Cloud Organization level. No CVE or patch has been issued.
Why it matters: Organizations using Config Connector with high-privilege service accounts could be exposed to full cloud-environment takeover if the report is accurate. Defenders using Google Cloud and Kubernetes should urgently review Config Connector deployments, reduce org-level permissions, and watch for vendor guidance or a fix.

Sources

In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum
SecurityWeek News 2026.06.19 84% relevant
It flags the same unpatched Google Cloud Config Connector issue, summarizing it as a flaw that can enable takeover of Google Cloud organizations.
Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed
2026.06.18 100% relevant
This article appears to be the first concrete report establishing the alleged Config Connector IAM-bypass issue, including the affected Google product, the claimed impact, and the fact that it remains unfixed.
← Back to all stories