CVE-2026-40547 PUBLISHED

Path Traversal in SOPlanning

Assigner: CERT-PL
Reserved: 14.04.2026 Published: 01.06.2026 Updated: 01.06.2026

SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. Critically, due to CVE-2026-40543 (Missing Authorization), any backup file can be read by any (unauthorized) user.

This issue affects SOPlanning version 1.55 and below.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
CVSS Score: 6.4

Product Status

Vendor SOPlanning
Product SOPlanning
Versions Default: unaffected
  • affected from 0 to 1.55 (incl.)

Credits

  • Łukasz Jaworski finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal