CVE-2026-15623
Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.
| CWE | CWE-89 |
| Vendor | google cloud |
| Product | google secops (chronicle soar) |
| Published | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for google cloud google secops (chronicle soar)
Be the first to know when new unknown vulnerabilities affecting google cloud google secops (chronicle soar) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google Cloud / Google SecOps (Chronicle SOAR)
0 < 6.3.85
References
Credits
๐ Jakub Domeracki