Impact
Improper privilege management in earlier releases of Google SecOps (Chronicle SOAR) allowed an authenticated attacker to craft an internal authentication header that elevates their privileges to system‑level administrative access. This flaw, a CWE‑346 weakness, can provide full control of the platform, enabling configuration changes, data access and service disruption. The vulnerability has been addressed in version 6.3.85 and is no longer exploitable in current deployments.
Affected Systems
Google Cloud users running Google SecOps (Chronicle SOAR) versions prior to 6.3.85 were potentially vulnerable; however, the patch has been rolled out and no customer action is required for current deployments.
Risk and Exploitability
The CVSS score of 9.4 underscores the severity of the issue. Although the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the timely release of the fix in 6.3.85 effectively mitigates exploitation risk. An attacker who was previously authenticated could have constructed a crafted header, but this is no longer feasible without the vulnerability.
OpenCVE Enrichment