PT-2026-64276 · Google · Looker

·

CVE-2026-15810

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Name of the Vulnerable Software and Affected Versions Google Cloud Looker versions prior to 25.6.103 Google Cloud Looker versions prior to 25.12.65 Google Cloud Looker versions prior to 25.18.68 Google Cloud Looker versions prior to 26.0.66 Google Cloud Looker versions prior to 26.2.47 Google Cloud Looker versions prior to 26.4.36 Google Cloud Looker versions prior to 26.6.28 Google Cloud Looker versions prior to 26.8.7
Description A Cross-Site Scripting (XSS) issue in both Looker-hosted and Self-hosted environments allows an attacker to execute arbitrary JavaScript via a maliciously crafted URL. This can lead to the takeover of administrative accounts.
Recommendations Upgrade self-hosted instances to versions 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, or 26.8.7.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15810

Affected Products

Looker