Security Advisory

CVE-2026-15623

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 06:27:00
Last updated 2026-08-17 15:23:57
Assigner GoogleCloud
CVSS score 9.4
State PUBLISHED

Description

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.