CVE-2026-15587

Summary

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.

This vulnerability was patched with version 6.3.85, and no customer action is needed.

Affected Software

VendorProductVersion RangeStatus
Google CloudGoogle SecOps (Chronicle SOAR)0 < 6.3.85affected

Weaknesses

  • CWE-346: CWE-346 Origin Validation Error

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References