SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15623

CRITICAL · CVSS 9.4 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A critical SQL Injection vulnerability exists in the legacy dashboard widget API of Google Cloud's SecOps (Chronicle SOAR) prior to version 6.3.85, allowing authenticated attackers to execute blind SQL queries via specially crafted request parameters. Organizations using affected versions should prioritize upgrading to 6.3.85 to mitigate the risk of unauthorized data access and potential exploitation. No immediate action is required from customers, as the patch has been implemented.

CVE
CVE-2026-15623
Severity
CRITICAL
CVSS
9.4
EPSS
0.22%

Original NVD Description

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.