Google · Looker · CVE-2026-15810
**Name of the Vulnerable Software and Affected Versions**
Google Cloud Looker versions prior to 25.6.103
Google Cloud Looker versions prior to 25.12.65
Google Cloud Looker versions prior to 25.18.68
Google Cloud Looker versions prior to 26.0.66
Google Cloud Looker versions prior to 26.2.47
Google Cloud Looker versions prior to 26.4.36
Google Cloud Looker versions prior to 26.6.28
Google Cloud Looker versions prior to 26.8.7
**Description**
A Cross-Site Scripting (XSS) issue in both Looker-hosted and Self-hosted environments allows an attacker to execute arbitrary JavaScript via a maliciously crafted URL. This can lead to the takeover of administrative accounts.
**Recommendations**
Upgrade self-hosted instances to versions 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, or 26.8.7.