PT-2026-68182 · Google · Google Secops

·

CVE-2026-15587

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear
Name of the Vulnerable Software and Affected Versions Google SecOps (Chronicle SOAR) versions prior to 6.3.85
Description Improper Privilege Management on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access. This is achieved by using a crafted internal authentication header.
Recommendations Update to version 6.3.85.

Fix

LPE

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15587

Affected Products

Google Secops