Executive brief
Google Chronicle SOAR is a security operations platform used to manage and respond to security incidents. A SQL injection vulnerability in a legacy dashboard widget API allows authenticated users to execute arbitrary SQL queries against the underlying database, potentially exposing sensitive security investigation data or enabling unauthorized data modification.
Technical details
A SQL injection vulnerability exists in a legacy dashboard widget API endpoint in Chronicle SOAR versions prior to 6.3.85. The vulnerability allows an authenticated attacker to inject malicious SQL code through a crafted request parameter to execute blind SQL queries. Attack requires authentication (authenticated attacker) and network access to the API endpoint. An attacker can extract sensitive data from the database or modify existing records. The vulnerability was patched in version 6.3.85; users should upgrade to this version or later.
Affected products
- Google Chronicle SOAR prior to 6.3.85
Timeline
- 2026-08-17: disclosed
- 2026: patched: Fixed in version 6.3.85