Junglewise Threat Intelligence

CVE-2026-40549: SOPlanning CSRF in groupe_save endpoints

CVE-2026-40549 · Severity: info · CVSS 5.1 · Published 2026-06-01

Technologies: SOPlanning. Vendors: SOPlanning.

Executive brief

SOPlanning, an online project management and team scheduling tool, is vulnerable to a security flaw that could allow an attacker to perform unauthorized actions. By tricking an authenticated user into visiting a malicious website, an attacker can silently create, modify, or delete group data within the application. This could lead to unauthorized changes in project organization or loss of administrative group configurations.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in SOPlanning versions up to and including 1.55. The vulnerability is located within the 'groupe_save' endpoints responsible for creating, modifying, and deleting groups. Because these endpoints do not implement sufficient CSRF protections (such as anti-forgery tokens), an attacker can craft a malicious webpage that triggers forged GET or POST requests to the application. If an authenticated user with appropriate permissions visits the attacker's site, the browser will automatically execute these requests in the context of the user's session, allowing the attacker to manipulate group data.

Affected products

  • SOPlanning SOPlanning All through 1.55

Timeline

  • 2026-06-01: advisory: Advisory published by CERT Polska

References

Related threats