Description
A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL.


Looker-hosted and Self-hosted were found to be vulnerable.
This issue has already been mitigated for Looker-hosted instances. No user action is required for these.


Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.
Published: 2026-07-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Cross‑Site Scripting (XSS) flaw allows malicious code to be injected into a URL that an administrator will open, executing the JavaScript with administrative privileges. The attack can result in full takeover of the Looker instance, enabling an attacker to modify settings, access sensitive data, or disrupt operations. The weakness is identified as CWE‑79, a classic reflected XSS vulnerability.

Affected Systems

Both Google Cloud Looker hosted services and self‑hosted installations are affected if they run any of the versions below the listed patches: 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, or 26.8.7. Google has already mitigated the issue for Looker‑hosted instances, so no action is needed for customers on that platform. Self‑hosted customers must upgrade to one of the patched releases or newer.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity flaw, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, meaning no public exploitation has been reported. Attackers can exploit the flaw by crafting a malicious link and convincing an administrator to visit it. User training and strict URL sanitization are critical mitigating controls. Implementing a robust Content Security Policy will also limit successful exploitation.

Generated by OpenCVE AI on August 3, 2026 at 20:27 UTC.

Remediation

Vendor Solution

This vulnerability has been mitigated for Looker-hosted instances, and no user action is required. For Self-hosted Looker instances, customers should upgrade to one of the patched versions or later: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.


OpenCVE Recommended Actions

  • Upgrade self‑hosted Looker installations to any of the patched releases listed in the vendor advisory (25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, 26.8.7+ or later).
  • Implement a strict Content Security Policy that disallows inline scripts and limits script sources to trusted origins to mitigate any residual XSS risk.
  • Ensure all administrative accounts use strong passwords and multi‑factor authentication to reduce the impact if a session is compromised.

Generated by OpenCVE AI on August 3, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Looker
Vendors & Products Google
Google cloud Looker

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.
Title Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Google Cloud Looker
cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2026-07-24T12:35:11.062Z

Reserved: 2026-07-15T10:03:09.218Z

Link: CVE-2026-15810

cve-icon Vulnrichment

Updated: 2026-07-24T12:35:03.396Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-24T12:16:47.543

Modified: 2026-07-27T20:37:16.927

Link: CVE-2026-15810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')