๐Ÿ” CVE Alert

CVE-2026-15587

UNKNOWN 0.0

Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.

CWE CWE-346
Vendor google cloud
Product google secops (chronicle soar)
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud google secops (chronicle soar)

Be the first to know when new unknown vulnerabilities affecting google cloud google secops (chronicle soar) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Google SecOps (Chronicle SOAR)
0 < 6.3.85

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_23_2026

Credits

๐Ÿ” Jakub Domeracki