VYPR

Chronicle SOAR

by Google

CVEs (2)

  • CVE-2026-15623CriAug 17, 2026
    risk 0.61cvss —epss 0.00

    A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter. This vulnerability…

  • CVE-2026-15587CriAug 5, 2026
    risk 0.61cvss —epss 0.00

    Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrative access using a crafted internal authentication header. This vulnerability…