Junglewise Threat Intelligence

CVE-2026-40543: SOPlanning missing authorization in backup functionalities

CVE-2026-40543 · Severity: info · CVSS 8.8 · Published 2026-06-01

Technologies: SOPlanning. Vendors: SOPlanning.

Executive brief

SOPlanning, an online project management and team scheduling tool, contains a security flaw where backup functions do not require authentication. This allows any unauthorized person on the internet to download full system backups. These backups contain sensitive information including user databases, password hashes, and configuration files, which could lead to a total compromise of the platform and its data.

Technical details

A missing authorization vulnerability (CWE-862) exists in SOPlanning versions 1.55 and earlier. The application fails to validate permissions on backup-related endpoints, allowing unauthenticated remote attackers to directly query these endpoints. Successful exploitation enables the retrieval of backup archives containing the user database (including usernames and password hashes) and the 'config.csv' file. This vulnerability can also be chained with other flaws, such as path traversal, to facilitate further attacks on the system.

Affected products

  • SOPlanning SOPlanning 1.55 and below

Timeline

  • 2026-06-01: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-06-01: advisory

References

Related threats