Description
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.




This vulnerability was patched with version 6.3.85, and no customer action is needed.
Published: 2026-08-05
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper privilege management in earlier releases of Google SecOps (Chronicle SOAR) allowed an authenticated attacker to craft an internal authentication header that elevates their privileges to system‑level administrative access. This flaw, a CWE‑346 weakness, can provide full control of the platform, enabling configuration changes, data access and service disruption. The vulnerability has been addressed in version 6.3.85 and is no longer exploitable in current deployments.

Affected Systems

Google Cloud users running Google SecOps (Chronicle SOAR) versions prior to 6.3.85 were potentially vulnerable; however, the patch has been rolled out and no customer action is required for current deployments.

Risk and Exploitability

The CVSS score of 9.4 underscores the severity of the issue. Although the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the timely release of the fix in 6.3.85 effectively mitigates exploitation risk. An attacker who was previously authenticated could have constructed a crafted header, but this is no longer feasible without the vulnerability.

Generated by OpenCVE AI on August 5, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce least privilege by limiting users to only the roles they require, reducing the impact of any discovered flaws.
  • Enable and review audit logs for authentication header activity to detect anomalous or unauthorized requests.
  • Remain vigilant to Google Cloud security advisories and apply any future updates or remediations as recommended.

Generated by OpenCVE AI on August 5, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google Cloud
Google Cloud google Secops (chronicle Soar)
Vendors & Products Google Cloud
Google Cloud google Secops (chronicle Soar)

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability was patched with version 6.3.85, and no customer action is needed.
Title Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header
Weaknesses CWE-346
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Clear'}


Subscriptions

Google Cloud Google Secops (chronicle Soar)
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-08-05T16:07:31.098Z

Reserved: 2026-07-13T12:21:09.118Z

Link: CVE-2026-15587

cve-icon Vulnrichment

Updated: 2026-08-05T16:07:28.455Z

cve-icon NVD

Status : Received

Published: 2026-08-05T16:16:51.147

Modified: 2026-08-05T16:16:51.147

Link: CVE-2026-15587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:06:20Z

Weaknesses