CVE-2026-15623
9.4Google Cloud · Google SecOps (Chronicle SOAR)
A SQL injection vulnerability in a legacy dashboard widget API of Google SecOps (Chronicle SOAR) allows authenticated attackers to execute unauthorized blind SQL queries.
Executive summary
A critical SQL injection vulnerability in Google SecOps (Chronicle SOAR) allows authenticated attackers to manipulate database queries via a legacy dashboard widget API.
Vulnerability
The vulnerability exists within a legacy dashboard widget API that fails to properly neutralize input in a request parameter. An authenticated attacker can leverage this flaw to execute blind SQL queries against the underlying database.
Business impact
Successful exploitation could lead to unauthorized access to sensitive security data and potential compromise of the SOAR platform configuration. With a CVSS score of 9.4, the risk is critical as it impacts the integrity and confidentiality of security operations data.
Remediation
Immediate Action: Verify that the system is running version 6.3.85 or later, as the vendor has confirmed the patch is already applied in this release.
Proactive Monitoring: Review audit logs for suspicious API calls directed at dashboard widgets to identify potential unauthorized activity.
Compensating Controls: Ensure that access to the Google SecOps platform is restricted to authorized personnel using strong multi-factor authentication to limit the pool of potential attackers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
While the vendor has already released a patch, organizations should confirm their version status immediately. Ensuring all instances are on version 6.3.85 or later is the definitive step to eliminate this risk.