PT-2026-68182 · Google · Google Secops
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear |
Name of the Vulnerable Software and Affected Versions
Google SecOps (Chronicle SOAR) versions prior to 6.3.85
Description
Improper Privilege Management on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access. This is achieved by using a crafted internal authentication header.
Recommendations
Update to version 6.3.85.
Fix
LPE
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Secops