CVE-2026-40543
Missing Authorization in SOPlanning
CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
21th
SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information. This issue affects SOPlanning version 1.55 and below.
| CWE | CWE-862 |
| Vendor | soplanning |
| Product | soplanning |
| Published | Jun 1, 2026 |
| Last Updated | Jun 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for soplanning soplanning
Be the first to know when new unknown vulnerabilities affecting soplanning soplanning are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
SOPlanning / SOPlanning
0 ≤ 1.55
References
Credits
Łukasz Jaworski