CVE-2026-15587
Published on August 5, 2026

Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.

NVD

Vulnerability Analysis

CVE-2026-15587 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

Origin Validation Error

The software does not properly verify that the source of data or communication is valid.


Affected Versions

Google Cloud Google SecOps (Chronicle SOAR):