CVE-2026-15587: Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-
Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header.
This vulnerability was patched with version 6.3.85, and no customer action is needed.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-15587
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15587 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Improper Privilege Management
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic …nvd · 2026-08-05
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…nvd · 2026-08-05
- criticalCVE-2026-7329: An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfa…nvd · 2026-08-05
- highCVE-2026-7327: An improper privilege management vulnerability in the REST API document processing pipeline of …nvd · 2026-08-05
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…nvd · 2026-08-03
- highCVE-2026-22622: Improper input validation in one of the session management interface of Eaton's Tripp Lite ser…nvd · 2026-07-30
More from NVD Recent CVEs
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…2026-08-05
- criticalCVE-2026-9195: A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 1…2026-08-05
- criticalCVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic …2026-08-05
- criticalCVE-2026-9192: An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server befo…2026-08-05
- criticalCVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server bef…2026-08-05