AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15587

CRITICAL · CVSS 9.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform are susceptible to improper privilege management, enabling authenticated attackers to escalate their privileges to system-level administrative access via a manipulated internal authentication header. Organizations utilizing affected versions should prioritize updating to the patched version to mitigate the risk of unauthorized access and potential exploitation. Immediate action is recommended for all users of the affected software to ensure security compliance.

CVE
CVE-2026-15587
Severity
CRITICAL
CVSS
9.4
EPSS
0.16%

Original NVD Description

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.