Junglewise Threat Intelligence

CVE-2026-15810: Google Cloud Looker XSS leading to administrative account takeover

CVE-2026-15810 · Severity: high · CVSS 8.7 · Published 2026-07-24

Technologies: Google Cloud Platform. Vendors: Google.

Executive brief

Google Cloud Looker, a business intelligence and data analytics platform, is affected by a security flaw that could allow an attacker to take over administrative accounts. By tricking a Looker administrator into clicking a specially crafted link, an attacker can execute malicious code within the administrator's browser session. This could lead to unauthorized access to sensitive corporate data, modification of analytics models, or full control over the Looker instance.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in both Looker-hosted and self-hosted versions of Google Cloud Looker. The flaw allows an unauthenticated attacker to craft a malicious URL that, when visited by an authenticated administrator, executes arbitrary JavaScript in the context of the victim's session. This execution can be leveraged to perform actions on behalf of the administrator, potentially leading to full account takeover. Google has mitigated the issue for Looker-hosted instances, but self-hosted customers must manually upgrade to patched versions (e.g., 26.8.7+, 26.6.28+, 25.6.103+).

Affected products

  • Google Cloud Looker prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7

Timeline

  • 2026-07-22: advisory: Google Cloud security bulletin GCP-2026-049 published
  • 2026-07-24: disclosed: CVE-2026-15810 published to NVD

References

Related threats