CVE-2026-15587
Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.
| CWE | CWE-346 |
| Vendor | google cloud |
| Product | google secops (chronicle soar) |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud google secops (chronicle soar)
Be the first to know when new unknown vulnerabilities affecting google cloud google secops (chronicle soar) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Google SecOps (Chronicle SOAR)
0 < 6.3.85
References
Credits
๐ Jakub Domeracki