Junglewise Threat Intelligence

CVE-2026-50644: SOPlanning SQL injection in audit retention configuration

CVE-2026-50644 · Severity: info · CVSS 8.6 · Published 2026-07-09

Technologies: SOPlanning. Vendors: SOPlanning.

Executive brief

SOPlanning, an online project management and team scheduling tool, is vulnerable to a security flaw that allows authorized users to inject malicious database commands. An attacker with administrative permissions can modify the audit configuration to execute unauthorized database queries. This could lead to the theft of sensitive project data, modification of schedules, or disruption of the planning service when the audit logs are viewed.

Technical details

A stored SQL injection vulnerability exists in SOPlanning within the audit retention configuration form. An attacker possessing 'parameters_all' privileges can submit malicious SQL commands through the configuration interface, which are then saved to the database. The payload is executed when the audit functionality is subsequently accessed by any user. This vulnerability is classified as CWE-89 and was addressed in version 1.56.01. The attack requires high privileges but can result in high impact on confidentiality and integrity of the underlying database.

Affected products

  • SOPlanning SOPlanning All versions before 1.56.01

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory: Published by CERT Polska and NVD
  • 2026-07-09: patched: Fixed in version 1.56.01

References

Related threats