CVE-2026-15623Disclosure

MEDIUMCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability was patched in version 6.3.85, and no customer action is needed.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-08-17: 5PoC Mentioned / Linked · 2026-08-17: 1Exploit Tool / Code · 2026-08-17: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 408-17
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Patch
120.0%
PoC
120.0%
Referenced assets3 URLs
Full discourse5 posts
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-15623 [HIGH PRIORITY] #Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widge... 🔗 https://exploitgrid.net/cve/CVE-2026-15623

    Post summary

    The post announces CVE-2026-15623, an authenticated blind SQL injection in Google Cloud SecOps SOAR Dashboard, and includes a link to a potential PoC/exploit on Exploitgrid.

    1000021
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19977 CVE-2024-13784 CVE-2026-15623 CVE-2026-19959 CVE-2026-19961 ..🧵👇

    Post summary

    The digest enumerates several CVEs but provides no technical details, exploirtion evidence, or mitigations.

    1000032
    33 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-15623 SQL Injection in Google Cloud Google SecOps (Chronicle SOAR) Prior to 6.3.85 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-15623

    Post summary

    The tweet announces a new SQL injection vulnerability (CVE‑2026‑15623) affecting Google Cloud's Google SecOps (Chronicle SOAR) prior to version 6.3.85 and links to a Vulmon database entry.

    0000097
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15623 A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows… https://www.cve.org/CVERecord?id=CVE-2026-15623

    Post summary

    The tweet announces CVE‑2026‑15623 as a SQL injection vulnerability in older Google SecOps (Chronicle SOAR) dashboard widget API versions, linking to the official CVE record.

    000001.1K
    58.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Google SecOps (Chronicle SOAR) legacy dashboard widget API SQL injection (CVE-2026-15623) SQL injection in the legacy dashboard widget API lets an authenticated remote attacker send crafted parameters to run blind SQL queries, reading or modifying application DB data. OS command execution is possible only if the DB account holds sufficient privileges. 👉Affected: Google SecOps / Chronicle SOAR < 6.3.85 | Upgrade to 6.3.85+

    Post summary

    The post announces a high‑severity CVE involving SQL injection in Google SecOps/Chronicle SOAR and recommends upgrading to version 6.3.85+ to remediate the issue.

    0000098
    291 followersView on X

Explore more