CVE-2026-15587
Received Received - Intake

Improper Privilege Management in Google SecOps (Chronicle SOAR)

Vulnerability report for CVE-2026-15587, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: GoogleCloud

Description

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google chronicle_soar to 6.3.85 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper privilege management vulnerability in Google SecOps (Chronicle SOAR) versions before 6.3.85. An authenticated attacker can escalate privileges to system-level admin access by exploiting a crafted internal authentication header.

Detection Guidance

Detection is not required as the vulnerability was patched internally by Google in version 6.3.85. No customer action or commands are needed for detection.

Impact Analysis

An attacker with access could gain full administrative control over the system, potentially accessing sensitive data, disrupting operations, or performing unauthorized actions. The high CVSS score (9.4) indicates severe impact.

Compliance Impact

This vulnerability could potentially lead to unauthorized access to sensitive data, which may impact compliance with regulations like GDPR and HIPAA by exposing personal or health information. However, the issue was patched in version 6.3.85, mitigating the risk.

Mitigation Strategies

No immediate steps are required. The vulnerability was patched in version 6.3.85, and no customer action is needed to mitigate it.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15587. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart