A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter.
This vulnerability was patched in version 6.3.85, and no customer action is needed.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google Cloud
Google Cloud google Secops (chronicle Soar) |
|
| Vendors & Products |
Google Cloud
Google Cloud google Secops (chronicle Soar) |
Mon, 17 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed. | |
| Title | Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget Query Service | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2026-08-17T15:23:57.708Z
Reserved: 2026-07-13T17:22:36.577Z
Link: CVE-2026-15623
Updated: 2026-08-17T15:23:52.500Z
Status : Received
Published: 2026-08-17T07:17:12.020
Modified: 2026-08-17T16:16:49.250
Link: CVE-2026-15623
No data.
OpenCVE Enrichment
Updated: 2026-08-17T08:15:18Z