๐Ÿ” CVE Alert

CVE-2026-15623

UNKNOWN 0.0

Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.

CWE CWE-89
Vendor google cloud
Product google secops (chronicle soar)
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for google cloud google secops (chronicle soar)

Be the first to know when new unknown vulnerabilities affecting google cloud google secops (chronicle soar) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google Cloud / Google SecOps (Chronicle SOAR)
0 < 6.3.85

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.cloud.google.com: https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_23_2026

Credits

๐Ÿ” Jakub Domeracki