What is CVE-2026-15623?
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. The vulnerability was patched in version 6.3.85, and affected systems should be updated immediately.
Azərbaycanca: Google Cloud Platform-dakı Google SecOps (Chronicle SOAR) xidmətinin 6.3.85-dən əvvəlki versiyalarında köhnə dashboard widget API-da autentifikasiya olunmuş təcavüzkara xüsusi hazırlanmış sorğu parametri vasitəsilə kor SQL sorğuları icra etməyə imkan verən SQL Injection zəifliyi aşkarlanıb. Versiya 6.3.85-də bu zəiflik aradan qaldırılıb, təsirlənən sistemlərin dərhal yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of Google SecOps are affected by CVE-2026-15623?
This SQL Injection vulnerability affects Google SecOps (Chronicle SOAR) versions prior to 6.3.85.
Does exploiting CVE-2026-15623 require authentication?
Yes, exploiting this vulnerability requires the attacker to be authenticated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.