A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google… (CVE-2026-15623)
A SQL Injection vulnerability exists in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85. This flaw allows an authenticated attacker to execute blind SQL queries by crafting a specific request parameter. The vulnerability has been patched in version 6.3.85, and no customer action is required.
AI Analysis
Technical Summary
CVE-2026-15623 is a critical SQL Injection vulnerability affecting a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) prior to version 6.3.85. An authenticated attacker can exploit this flaw to perform blind SQL injection attacks via crafted request parameters. The issue was resolved in version 6.3.85. There are no known exploits in the wild, and the vulnerability is classified under CWE-89 (SQL Injection).
Potential Impact
Successful exploitation allows an authenticated attacker to execute blind SQL queries against the backend database, potentially leading to unauthorized data access or manipulation. The vulnerability is rated critical due to the high impact on confidentiality, integrity, and availability of the system.
Mitigation Recommendations
This vulnerability has been officially fixed in Google Cloud Google SecOps (Chronicle SOAR) version 6.3.85. Users should upgrade to version 6.3.85 or later. No further customer action is needed beyond applying this update.
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google… (CVE-2026-15623)
Description
A SQL Injection vulnerability exists in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85. This flaw allows an authenticated attacker to execute blind SQL queries by crafting a specific request parameter. The vulnerability has been patched in version 6.3.85, and no customer action is required.
CVSS v4.0
Affected software
pkg:github/google/chronicle-soarRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15623 is a critical SQL Injection vulnerability affecting a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) prior to version 6.3.85. An authenticated attacker can exploit this flaw to perform blind SQL injection attacks via crafted request parameters. The issue was resolved in version 6.3.85. There are no known exploits in the wild, and the vulnerability is classified under CWE-89 (SQL Injection).
Potential Impact
Successful exploitation allows an authenticated attacker to execute blind SQL queries against the backend database, potentially leading to unauthorized data access or manipulation. The vulnerability is rated critical due to the high impact on confidentiality, integrity, and availability of the system.
Mitigation Recommendations
This vulnerability has been officially fixed in Google Cloud Google SecOps (Chronicle SOAR) version 6.3.85. Users should upgrade to version 6.3.85 or later. No further customer action is needed beyond applying this update.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8f9j-vmpc-422v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-15623"]
- Ecosystems
- []
- Database Specific Severity
- CRITICAL
- Cvss Version
- 4.0
Threat ID: 6a833371bf8831d5392a86b3
Added to database: 08/17/2026, 16:14:41 UTC
Last enriched: 08/17/2026, 16:37:29 UTC
Last updated: 08/17/2026, 17:21:03 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.