GCP-2026-049

Google Version 4 imported change current

Imported from official source

Published: 2026-07-22Description Description Severity Notes A reflected Cross-Site Scripting (XSS) vulnerability was discovered in Google Cloud Looker. An attacker could craft a malicious URL that, when opened by an authenticated administrator, would allow the attacker to execute arbitrary scripts on their behalf and potentially compromise the administrator account. What should I do? …

This version

Version
4 of 4
Recorded
September 28, 2026 11:00
Change
Imported change
Content hash
f2f7d0b1a4854682dca402ad6d7b2c8a
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.