PT-2026-45360 · Soplanning · Soplanning

·

CVE-2026-40547

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SOPlanning versions prior to 1.56
Description Path Traversal exists in backup endpoints, allowing an authenticated remote attacker to read and execute files previously added via the backup functionality. Additionally, a missing authorization issue allows any unauthorized user to read any backup file.
Recommendations Update SOPlanning to a version later than 1.55.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40547

Affected Products

Soplanning