What is CVE-2026-15587?
This vulnerability is an Improper Privilege Management flaw in Google SecOps (Chronicle SOAR) versions prior to 6.3.85. On Google Cloud Platform, an authenticated attacker can escalate privileges to system-level administrative access using a crafted internal authentication header. Affected users are strongly advised to update to the patched version immediately.
Azərbaycanca: Bu zəiflik Google SecOps (Chronicle SOAR) platformasının 6.3.85 versiyasından əvvəlki versiyalarında aşkar edilmiş 'Improper Privilege Management' (Qeyri-düzgün İmtiyaz İdarəetməsi) qüsurudur. Google Cloud Platform-da autentifikasiya olunmuş təcavüzkar, xüsusi hazırlanmış daxili autentifikasiya başlığı (internal authentication header) ilə sistem səviyyəsində inzibati giriş əldə edə bilər. İstifadəçilərə dərhal təsirlənmiş versiyaları patched edilmiş versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which platform is affected by CVE-2026-15587?
This vulnerability affects the Google SecOps (Chronicle SOAR) platform.
What can an attacker gain by exploiting this flaw?
An authenticated attacker can gain system-level administrative access using a crafted internal authentication header.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.