CVE-2026-40543 PUBLISHED

Missing Authorization in SOPlanning

Assigner: CERT-PL
Reserved: 14.04.2026 Published: 01.06.2026 Updated: 01.06.2026

SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information.

This issue affects SOPlanning version 1.55 and below.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor SOPlanning
Product SOPlanning
Versions Default: unaffected
  • affected from 0 to 1.55 (incl.)

Credits

  • Łukasz Jaworski finder

References

Problem Types

  • CWE-862 Missing Authorization CWE