CVE-2026-15810
Received Received - Intake

Reflected XSS in Google Cloud Looker

Vulnerability report for CVE-2026-15810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: GoogleCloud

Description

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
google cloud_looker From 25.6.103 (inc)
google cloud_looker From 25.12.65 (inc)
google cloud_looker From 25.18.68 (inc)
google cloud_looker From 26.0.66 (inc)
google cloud_looker From 26.2.47 (inc)
google cloud_looker From 26.4.36 (inc)
google cloud_looker From 26.6.28 (inc)
google cloud_looker From 26.8.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions before specific patched releases. An attacker can craft a malicious URL that, when opened by a Looker administrator, executes arbitrary JavaScript code. This could lead to administrative account takeover by exploiting the administrator's session.

Detection Guidance

For Looker-hosted instances, no detection is needed as the issue is already mitigated. For self-hosted instances, monitor network traffic for unusual JavaScript execution or unauthorized administrative actions. Check Looker logs for suspicious URLs or script injections. Use web application firewalls to detect XSS attempts targeting Looker interfaces.

Impact Analysis

If you are a Looker administrator, an attacker could trick you into clicking a malicious link, allowing them to run arbitrary scripts in your browser. This could result in unauthorized access to your account, data theft, or further compromise of the Looker instance. Users of self-hosted instances are at higher risk if they do not apply the patches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations must ensure Looker instances are patched to prevent potential compliance breaches due to data exposure or unauthorized access.

Mitigation Strategies
  • For Looker-hosted instances, no action is required as the vulnerability is already mitigated.
  • For self-hosted instances, upgrade to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+ immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart