๐Ÿ” CVE Alert

CVE-2026-15810

UNKNOWN 0.0

Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.

CWE CWE-79
Vendor google cloud
Product looker
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud looker

Be the first to know when new unknown vulnerabilities affecting google cloud looker are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Looker
0 < 25.6.103 0 < 25.12.65 0 < 25.18.68 0 < 26.0.66 0 < 26.2.47 0 < 26.4.36 0 < 26.6.28 0 < 26.8.7
Google Cloud / Looker
0 < 25.6.103 0 < 25.12.65 0 < 25.18.68 0 < 26.0.66 0 < 26.2.47 0 < 26.4.36 0 < 26.6.28 0 < 26.8.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/support/bulletins#gcp-2026-049 docs.cloud.google.com: https://docs.cloud.google.com/looker/docs/release-notes#July_22_2026

Credits

๐Ÿ” Sivanesh Ashok ๐Ÿ” Sreeram KL