In plain language
What this advisory means
A security issue was found in Google Security Operations SOAR where a logged-in attacker could gain full system administrator rights by sending a specially crafted internal authentication header. Google fixed this issue in version 6.3.85 and automatically upgraded all customers to this fixed version. Customers do not need to take any action.
Technical explanation
How the issue affects the environment
The vulnerability is an improper privilege management flaw in Google Security Operations SOAR. Authenticated attackers could escalate their privileges to system-level administrative access by exploiting a crafted internal authentication header. This flaw allows them to gain administrative control beyond their authorized permissions. Google mitigated the vulnerability in software update version 6.3.85, deploying the fix automatically to all customer environments.
Operational impact
Why teams should care
If exploited, this vulnerability could allow authenticated attackers to gain full administrative control over the affected Google Security Operations SOAR system, potentially compromising security operations data, altering system configurations, or disrupting security services. Since Google automatically upgraded all customers to the patched version, the risk is minimized for those using version 6.3.85 or later.
Immediate action
No customer action is required. Google has automatically upgraded all customers to version 6.3.85 or higher, which contains the fix for this vulnerability.
Affected and fixed releases
Temporary risk reduction
The official source does not specify any workaround. Since upgrades were automatic, no manual mitigation steps are necessary for customers.
Evidence and validation checklist
- Official Google Cloud Security Bulletin dated 2026-09-16
- Description of improper privilege management vulnerability in Google Security Operations SOAR
- Fix applied in version 6.3.85
- Automatic upgrade of all customers to fixed version
- No customer action required
Authoritative reference
Google Cloud Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
