PT-2026-64276 · Google · Looker
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber |
Name of the Vulnerable Software and Affected Versions
Google Cloud Looker versions prior to 25.6.103
Google Cloud Looker versions prior to 25.12.65
Google Cloud Looker versions prior to 25.18.68
Google Cloud Looker versions prior to 26.0.66
Google Cloud Looker versions prior to 26.2.47
Google Cloud Looker versions prior to 26.4.36
Google Cloud Looker versions prior to 26.6.28
Google Cloud Looker versions prior to 26.8.7
Description
A Cross-Site Scripting (XSS) issue in both Looker-hosted and Self-hosted environments allows an attacker to execute arbitrary JavaScript via a maliciously crafted URL. This can lead to the takeover of administrative accounts.
Recommendations
Upgrade self-hosted instances to versions 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, or 26.8.7.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Looker