CVE-2026-15810 PUBLISHED

Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover

Assigner: GoogleCloud
Reserved: 15.07.2026 Published: 24.07.2026 Updated: 24.07.2026

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted URL.

Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these.

Self-hosted instances must be upgraded to the patched versions: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/U:Amber
CVSS Score: 8.7

Product Status

Vendor Google Cloud
Product Looker
Versions Default: unaffected
  • affected from 0 to 25.6.103 (excl.)
  • affected from 0 to 25.12.65 (excl.)
  • affected from 0 to 25.18.68 (excl.)
  • affected from 0 to 26.0.66 (excl.)
  • affected from 0 to 26.2.47 (excl.)
  • affected from 0 to 26.4.36 (excl.)
  • affected from 0 to 26.6.28 (excl.)
  • affected from 0 to 26.8.7 (excl.)
Vendor Google Cloud
Product Looker
Versions Default: unaffected
  • affected from 0 to 25.6.103 (excl.)
  • affected from 0 to 25.12.65 (excl.)
  • affected from 0 to 25.18.68 (excl.)
  • affected from 0 to 26.0.66 (excl.)
  • affected from 0 to 26.2.47 (excl.)
  • affected from 0 to 26.4.36 (excl.)
  • affected from 0 to 26.6.28 (excl.)
  • affected from 0 to 26.8.7 (excl.)

Solutions

This vulnerability has been mitigated for Looker-hosted instances, and no user action is required.

For Self-hosted Looker instances, customers should upgrade to one of the patched versions or later: 25.6.103+, 25.12.65+, 25.18.68+, 26.0.66+, 26.2.47+, 26.4.36+, 26.6.28+, or 26.8.7+.

Credits

  • Sivanesh Ashok reporter
  • Sreeram KL reporter

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)