Executive brief
Google Security Operations SOAR is a cloud-native incident response platform used to automate security investigations and response workflows. A vulnerability allowed authenticated users to escalate their privileges to system-level administrative access, potentially enabling attackers to take over the entire SOAR platform and access all incident data and configurations.
Technical details
An improper privilege management vulnerability in Google Security Operations SOAR allowed authenticated attackers to escalate privileges to system-level administrative access. The vulnerability could be exploited by crafting a malicious internal authentication header and sending it to the SOAR service. An attacker with valid credentials could achieve complete system compromise and access to all SOAR functionality and data. The vulnerability was patched in version 6.3.85, and all customers have been automatically upgraded with no manual action required.
Affected products
- Google Security Operations SOAR before 6.3.85
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Version 6.3.85 or higher